NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, where an unprivileged regular user can access administrator- privileged registers, which may lead to denial of service, information disclosure, and data tampering.
References
| Link | Resource |
|---|---|
| https://nvidia.custhelp.com/app/answers/detail/a_id/5353 | Patch Vendor Advisory |
| https://security.gentoo.org/glsa/202310-02 | Third Party Advisory |
| https://nvidia.custhelp.com/app/answers/detail/a_id/5353 | Patch Vendor Advisory |
| https://security.gentoo.org/glsa/202310-02 | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 06:56
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://nvidia.custhelp.com/app/answers/detail/a_id/5353 - Patch, Vendor Advisory | |
| References | () https://security.gentoo.org/glsa/202310-02 - Third Party Advisory | |
| CVSS |
v2 : v3 : |
v2 : 4.6
v3 : 7.1 |
11 Oct 2022, 20:35
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : 4.6
v3 : 7.8 |
26 May 2022, 18:20
| Type | Values Removed | Values Added |
|---|---|---|
| References | (MISC) https://nvidia.custhelp.com/app/answers/detail/a_id/5353 - Patch, Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : 4.6
v3 : 7.1 |
| CPE | cpe:2.3:a:nvidia:virtual_gpu:14.0:*:*:*:*:*:*:* cpe:2.3:a:nvidia:gpu_display_driver:-:*:*:*:*:linux:*:* cpe:2.3:a:nvidia:gpu_display_driver:-:*:*:*:*:windows:*:* cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:* |
|
| CWE | NVD-CWE-noinfo |
17 May 2022, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2022-05-17 20:15
Updated : 2024-11-21 06:56
NVD link : CVE-2022-28184
Mitre link : CVE-2022-28184
CVE.ORG link : CVE-2022-28184
JSON object : View
Products Affected
nvidia
- gpu_display_driver
- virtual_gpu
CWE
