USN-4689-3: NVIDIA graphics drivers vulnerabilities

20 January 2021

Several security issues were fixed in NVIDIA graphics drivers.

Releases

Packages

Details

It was discovered that the NVIDIA GPU display driver for the Linux kernel
contained a vulnerability that allowed user-mode clients to access legacy
privileged APIs. A local attacker could use this to cause a denial of
service or escalate privileges. (CVE-2021-1052)

It was discovered that the NVIDIA GPU display driver for the Linux kernel
did not properly validate a pointer received from userspace in some
situations. A local attacker could use this to cause a denial of service.
(CVE-2021-1053)

Xinyuan Lyu discovered that the NVIDIA GPU display driver for the Linux
kernel did not properly restrict device-level GPU isolation. A local
attacker could use this to cause a denial of service or possibly expose
sensitive information. (CVE-2021-1056)

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 20.10
Ubuntu 20.04
Ubuntu 18.04

This update uses a new upstream release, which includes additional
bug fixes. After a standard system update you need to reboot your
computer to make all the necessary changes.

Related notices

  • USN-4689-2: linux-image-gke, linux-image-lowlatency, linux-image-5.6.0-1042-oem, linux-gcp-5.4, linux-aws, linux-image-5.4.0-60-lowlatency, linux-image-virtual-hwe-18.04, linux-image-generic-hwe-20.04, linux-image-5.4.0-1036-azure, linux-image-aws-lts-18.04, linux-image-5.8.0-36-lowlatency, linux-image-4.15.0-1104-azure, linux-image-5.4.0-1035-oracle, linux-image-5.8.0-1018-aws, linux-image-generic, linux-image-oem, linux-image-5.8.0-1015-oracle, linux-aws-5.4, linux-image-oem-20.04, linux-image-azure, linux-oem-5.6, linux-image-virtual, linux-image-5.4.0-1035-aws, linux-image-generic-hwe-18.04, linux-image-5.4.0-1034-gcp, linux-image-aws, linux-image-5.8.0-36-generic, linux-gcp, linux-azure-4.15, linux-image-5.8.0-1017-azure, linux-image-4.15.0-130-lowlatency, linux-image-virtual-hwe-20.04, linux-image-oracle, linux-oracle, linux-image-gcp, linux-image-4.15.0-130-generic, linux-image-oem-osp1, linux-image-oracle-lts-18.04, linux-hwe-5.4, linux-image-azure-lts-18.04, linux-image-5.8.0-1016-gcp, linux-image-lowlatency-hwe-18.04, linux-oracle-5.4, linux-image-4.15.0-1063-oracle, linux-azure, linux-image-5.4.0-60-generic, linux-image-4.15.0-1092-aws, linux-image-lowlatency-hwe-20.04, linux, linux-azure-5.4, linux-hwe-5.8
  • USN-4689-4: linux-image-gke, linux-image-lowlatency, linux-image-virtual-hwe-18.04, linux-image-5.8.0-1020-aws, linux-image-generic-hwe-20.04, linux-image-5.8.0-40-lowlatency, linux-image-5.4.0-64-lowlatency, linux-image-5.4.0-64-generic, linux-image-generic, linux-image-oem, linux, linux-image-azure, linux-image-oem-20.04, linux-image-virtual, linux-image-generic-hwe-18.04, linux-image-aws, linux-gcp, linux-oracle, linux-image-virtual-hwe-20.04, linux-image-oracle, linux-image-gcp, linux-image-4.15.0-134-lowlatency, linux-image-5.8.0-1017-oracle, linux-image-5.8.0-1019-azure, linux-image-oem-osp1, linux-hwe-5.4, linux-image-lowlatency-hwe-18.04, linux-azure, linux-image-5.8.0-1019-gcp, linux-image-5.8.0-40-generic, linux-image-generic-lpae-hwe-20.04, linux-image-lowlatency-hwe-20.04, linux-image-4.15.0-134-generic, linux-aws, linux-hwe-5.8
  • USN-4689-1: xserver-xorg-video-nvidia-450, xserver-xorg-video-nvidia-455, xserver-xorg-video-nvidia-440, nvidia-graphics-drivers-390, nvidia-graphics-drivers-460, xserver-xorg-video-nvidia-460, nvidia-graphics-drivers-450, xserver-xorg-video-nvidia-390