=========================================================================Ubuntu Security Notice USN-4689-1
January 11, 2021

nvidia-graphics-drivers-390, nvidia-graphics-drivers-450,
nvidia-graphics-drivers-460 vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.10
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

Several security issues were fixed in NVIDIA graphics drivers.

Software Description:
- nvidia-graphics-drivers-390: NVIDIA binary X.Org driver
- nvidia-graphics-drivers-450: NVIDIA binary X.Org driver
- nvidia-graphics-drivers-460: NVIDIA binary X.Org driver

Details:

It was discovered that the NVIDIA GPU display driver for the Linux kernel
contained a vulnerability that allowed user-mode clients to access legacy
privileged APIs. A local attacker could use this to cause a denial of
service or escalate privileges. (CVE-2021-1052)

It was discovered that the NVIDIA GPU display driver for the Linux kernel
did not properly validate a pointer received from userspace in some
situations. A local attacker could use this to cause a denial of service.
(CVE-2021-1053)

Xinyuan Lyu discovered that the NVIDIA GPU display driver for the Linux
kernel did not properly restrict device-level GPU isolation. A local
attacker could use this to cause a denial of service or possibly expose
sensitive information. (CVE-2021-1056)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.10:
  xserver-xorg-video-nvidia-390   390.141-0ubuntu0.20.10.1
  xserver-xorg-video-nvidia-440   450.102.04-0ubuntu0.20.10.1
  xserver-xorg-video-nvidia-450   450.102.04-0ubuntu0.20.10.1
  xserver-xorg-video-nvidia-455   460.32.03-0ubuntu0.20.10.1
  xserver-xorg-video-nvidia-460   460.32.03-0ubuntu0.20.10.1

Ubuntu 20.04 LTS:
  xserver-xorg-video-nvidia-390   390.141-0ubuntu0.20.04.1
  xserver-xorg-video-nvidia-440   450.102.04-0ubuntu0.20.04.1
  xserver-xorg-video-nvidia-450   450.102.04-0ubuntu0.20.04.1
  xserver-xorg-video-nvidia-455   460.32.03-0ubuntu0.20.04.1
  xserver-xorg-video-nvidia-460   460.32.03-0ubuntu0.20.04.1

Ubuntu 18.04 LTS:
  xserver-xorg-video-nvidia-390   390.141-0ubuntu0.18.04.1
  xserver-xorg-video-nvidia-440   450.102.04-0ubuntu0.18.04.1
  xserver-xorg-video-nvidia-450   450.102.04-0ubuntu0.18.04.1
  xserver-xorg-video-nvidia-455   460.32.03-0ubuntu0.18.04.1
  xserver-xorg-video-nvidia-460   460.32.03-0ubuntu0.18.04.1

This update uses a new upstream release, which includes additional
bug fixes. After a standard system update you need to reboot your
computer to make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-4689-1
  CVE-2021-1052, CVE-2021-1053, CVE-2021-1056

Package Information:
  https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-390/390.141-0ubuntu0.20.10.1
  https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-450/450.102.04-0ubuntu0.20.10.1
  https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-460/460.32.03-0ubuntu0.20.10.1
  https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-390/390.141-0ubuntu0.20.04.1
  https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-450/450.102.04-0ubuntu0.20.04.1
  https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-460/460.32.03-0ubuntu0.20.04.1
  https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-390/390.141-0ubuntu0.18.04.1
  https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-450/450.102.04-0ubuntu0.18.04.1
  https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-460/460.32.03-0ubuntu0.18.04.1

Ubuntu 4689-1: NVIDIA graphics drivers vulnerabilities

January 11, 2021
Several security issues were fixed in NVIDIA graphics drivers.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 20.10: xserver-xorg-video-nvidia-390 390.141-0ubuntu0.20.10.1 xserver-xorg-video-nvidia-440 450.102.04-0ubuntu0.20.10.1 xserver-xorg-video-nvidia-450 450.102.04-0ubuntu0.20.10.1 xserver-xorg-video-nvidia-455 460.32.03-0ubuntu0.20.10.1 xserver-xorg-video-nvidia-460 460.32.03-0ubuntu0.20.10.1 Ubuntu 20.04 LTS: xserver-xorg-video-nvidia-390 390.141-0ubuntu0.20.04.1 xserver-xorg-video-nvidia-440 450.102.04-0ubuntu0.20.04.1 xserver-xorg-video-nvidia-450 450.102.04-0ubuntu0.20.04.1 xserver-xorg-video-nvidia-455 460.32.03-0ubuntu0.20.04.1 xserver-xorg-video-nvidia-460 460.32.03-0ubuntu0.20.04.1 Ubuntu 18.04 LTS: xserver-xorg-video-nvidia-390 390.141-0ubuntu0.18.04.1 xserver-xorg-video-nvidia-440 450.102.04-0ubuntu0.18.04.1 xserver-xorg-video-nvidia-450 450.102.04-0ubuntu0.18.04.1 xserver-xorg-video-nvidia-455 460.32.03-0ubuntu0.18.04.1 xserver-xorg-video-nvidia-460 460.32.03-0ubuntu0.18.04.1 This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to reboot your computer to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4689-1

CVE-2021-1052, CVE-2021-1053, CVE-2021-1056

Severity
January 11, 2021

Package Information

https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-390/390.141-0ubuntu0.20.10.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-450/450.102.04-0ubuntu0.20.10.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-460/460.32.03-0ubuntu0.20.10.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-390/390.141-0ubuntu0.20.04.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-450/450.102.04-0ubuntu0.20.04.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-460/460.32.03-0ubuntu0.20.04.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-390/390.141-0ubuntu0.18.04.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-450/450.102.04-0ubuntu0.18.04.1 https://launchpad.net/ubuntu/+source/nvidia-graphics-drivers-460/460.32.03-0ubuntu0.18.04.1

Related News