MGASA-2022-0285 - Updated nvidia-current packages fix security vulnerabilities

Publication date: 18 Aug 2022
URL: https://advisories.mageia.org/MGASA-2022-0285.html
Type: security
Affected Mageia releases: 8
CVE: CVE‑2022‑31607,
     CVE‑2022‑31608,
     CVE‑2022‑31615,
     CVE‑2022‑34665,
     CVE‑2022‑34666

Updated nvidia-current packages fix security vulnerabilities:

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel
mode layer (nvidia.ko), where a local user with basic capabilities can cause
improper input validation, which may lead to denial of service, escalation
of privileges, data tampering, and limited information disclosure
(CVE‑2022‑31607).

NVIDIA GPU Display Driver for Linux contains a vulnerability in an optional
D-Bus configuration file, where a local user with basic capabilities can
impact protected D-Bus endpoints, which may lead to code execution, denial
of service, escalation of privileges, information disclosure, and data
tampering (CVE‑2022‑31608).

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel
mode layer, where a local user with basic capabilities can cause a null-
pointer dereference, which may lead to denial of service (CVE‑2022‑31615).

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel
mode layer, where a local user with basic capabilities can cause a null-
pointer dereference, which may lead to denial of service (CVE‑2022‑34665).

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability
in the kernel mode layer, where a local user with basic capabilities can
cause a null-pointer dereference, which may lead to denial of service
(CVE‑2022‑34666).

References:
- https://bugs.mageia.org/show_bug.cgi?id=30722
- https://nvidia.custhelp.com/app/answers/detail/a_id/5383
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE‑2022‑31607
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE‑2022‑31608
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE‑2022‑31615
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE‑2022‑34665
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE‑2022‑34666

SRPMS:
- 8/core/ldetect-lst-0.6.26.13-1.mga8
- 8/nonfree/nvidia-current-470.141.03-1.mga8.nonfree

Mageia 2022-0285: nvidia-current security update

Updated nvidia-current packages fix security vulnerabilities: NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where a local user...

Summary

Updated nvidia-current packages fix security vulnerabilities:
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where a local user with basic capabilities can cause improper input validation, which may lead to denial of service, escalation of privileges, data tampering, and limited information disclosure (CVE‑2022‑31607).
NVIDIA GPU Display Driver for Linux contains a vulnerability in an optional D-Bus configuration file, where a local user with basic capabilities can impact protected D-Bus endpoints, which may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering (CVE‑2022‑31608).
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where a local user with basic capabilities can cause a null- pointer dereference, which may lead to denial of service (CVE‑2022‑31615).
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where a local user with basic capabilities can cause a null- pointer dereference, which may lead to denial of service (CVE‑2022‑34665).
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a local user with basic capabilities can cause a null-pointer dereference, which may lead to denial of service (CVE‑2022‑34666).

References

- https://bugs.mageia.org/show_bug.cgi?id=30722

- https://nvidia.custhelp.com/app/answers/detail/a_id/5383

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE‑2022‑31607

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE‑2022‑31608

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE‑2022‑31615

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE‑2022‑34665

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE‑2022‑34666

Resolution

MGASA-2022-0285 - Updated nvidia-current packages fix security vulnerabilities

SRPMS

- 8/core/ldetect-lst-0.6.26.13-1.mga8

- 8/nonfree/nvidia-current-470.141.03-1.mga8.nonfree

Severity
Publication date: 18 Aug 2022
URL: https://advisories.mageia.org/MGASA-2022-0285.html
Type: security
CVE: CVE‑2022‑31607, CVE‑2022‑31608, CVE‑2022‑31615, CVE‑2022‑34665, CVE‑2022‑34666

Related News