MGASA-2021-0202 - Updated nvidia390 packages fix security vulnerabilities

Publication date: 02 May 2021
URL: https://advisories.mageia.org/MGASA-2021-0202.html
Type: security
Affected Mageia releases: 7, 8
CVE: CVE-2021-1076

Updated nvidia390 packages fix security vulnerabilities:

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel
mode layer (nvidia.ko) where improper access control may lead to denial of
service, information disclosure, or data corruption (CVE-2021-1076).

It also fixes a bug where vkCreateSwapchain could cause the X Server to
crash when an invalid imageFormat was provided and adds support for newer
kernels.

References:
- https://bugs.mageia.org/show_bug.cgi?id=28853
- https://nvidia.custhelp.com/app/answers/detail/a_id/5172
- https://www.nvidia.com/Download/driverResults.aspx/173111/en-us/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-1076

SRPMS:
- 7/nonfree/nvidia390-390.143-1.mga7.nonfree
- 8/nonfree/nvidia390-390.143-1.mga8.nonfree

Mageia 2021-0202: nvidia390 security update

Updated nvidia390 packages fix security vulnerabilities: NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko) where improper access co...

Summary

Updated nvidia390 packages fix security vulnerabilities:
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko) where improper access control may lead to denial of service, information disclosure, or data corruption (CVE-2021-1076).
It also fixes a bug where vkCreateSwapchain could cause the X Server to crash when an invalid imageFormat was provided and adds support for newer kernels.

References

- https://bugs.mageia.org/show_bug.cgi?id=28853

- https://nvidia.custhelp.com/app/answers/detail/a_id/5172

- https://www.nvidia.com/Download/driverResults.aspx/173111/en-us/

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-1076

Resolution

MGASA-2021-0202 - Updated nvidia390 packages fix security vulnerabilities

SRPMS

- 7/nonfree/nvidia390-390.143-1.mga7.nonfree

- 8/nonfree/nvidia390-390.143-1.mga8.nonfree

Severity
Publication date: 02 May 2021
URL: https://advisories.mageia.org/MGASA-2021-0202.html
Type: security
CVE: CVE-2021-1076

Related News