fkie_cve-2016-7389
Vulnerability from fkie_nvd
Published
2016-11-08 20:59
Modified
2025-04-12 10:46
Summary
For the NVIDIA Quadro, NVS, GeForce, and Tesla products, NVIDIA GPU Display Driver on Linux R304 before 304.132, R340 before 340.98, R367 before 367.55, R361_93 before 361.93.03, and R370 before 370.28 contains a vulnerability in the kernel mode layer (nvidia.ko) handler for mmap() where improper input validation may allow users to gain access to arbitrary physical memory, leading to an escalation of privileges.
Impacted products
Vendor Product Version
nvidia gpu_driver 304.79
nvidia gpu_driver 340.52
nvidia gpu_driver 361.91
nvidia gpu_driver 365.19
nvidia gpu_driver 368.81
linux linux_kernel *



{
  "configurations": [
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:nvidia:gpu_driver:304.79:*:*:*:*:*:*:*",
              "matchCriteriaId": "1ED0EE81-C22D-453F-B665-36FC6C533CCE",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:nvidia:gpu_driver:340.52:*:*:*:*:*:*:*",
              "matchCriteriaId": "2A2A9CCB-D960-4643-AF80-204D516A8369",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:nvidia:gpu_driver:361.91:*:*:*:*:*:*:*",
              "matchCriteriaId": "5C93165D-1D1B-4464-8F75-D25FF3692361",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:nvidia:gpu_driver:365.19:*:*:*:*:*:*:*",
              "matchCriteriaId": "4A94D9D5-53A5-4A3D-A3BA-C5CD75AA477D",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:nvidia:gpu_driver:368.81:*:*:*:*:*:*:*",
              "matchCriteriaId": "34739729-7504-4313-8AF0-161DE9A1748C",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        },
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "155AD4FB-E527-4103-BCEF-801B653DEA37",
              "vulnerable": false
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "cveTags": [],
  "descriptions": [
    {
      "lang": "en",
      "value": "For the NVIDIA Quadro, NVS, GeForce, and Tesla products, NVIDIA GPU Display Driver on Linux R304 before 304.132, R340 before 340.98, R367 before 367.55, R361_93 before 361.93.03, and R370 before 370.28 contains a vulnerability in the kernel mode layer (nvidia.ko) handler for mmap() where improper input validation may allow users to gain access to arbitrary physical memory, leading to an escalation of privileges."
    },
    {
      "lang": "es",
      "value": "Para los productos NVIDIA Quadro, NVS, GeForce y Tesla, NVIDIA GPU Display Driver en Linux R304 en versiones anteriores a 304.132, R340 en versiones anteriores a 340.98, R367 en versiones anteriores a 367.55, R361_93 en versiones anteriores a 361.93.03 y R370 en versiones anteriores a 370.28 contiene una vulnerabilidad en el controlador de la capa de modo kernel (nvidia.ko) para mmap() donde una validaci\u00f3n de entrada inadecuada podr\u00eda permitir a usuarios obtener acceso a memoria f\u00edsica arbitraria, conduciendo a una escalada de privilegios."
    }
  ],
  "id": "CVE-2016-7389",
  "lastModified": "2025-04-12T10:46:40.837",
  "metrics": {
    "cvssMetricV2": [
      {
        "acInsufInfo": false,
        "baseSeverity": "HIGH",
        "cvssData": {
          "accessComplexity": "LOW",
          "accessVector": "LOCAL",
          "authentication": "NONE",
          "availabilityImpact": "COMPLETE",
          "baseScore": 7.2,
          "confidentialityImpact": "COMPLETE",
          "integrityImpact": "COMPLETE",
          "vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
          "version": "2.0"
        },
        "exploitabilityScore": 3.9,
        "impactScore": 10.0,
        "obtainAllPrivilege": false,
        "obtainOtherPrivilege": false,
        "obtainUserPrivilege": false,
        "source": "nvd@nist.gov",
        "type": "Primary",
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "cvssData": {
          "attackComplexity": "LOW",
          "attackVector": "LOCAL",
          "availabilityImpact": "HIGH",
          "baseScore": 7.8,
          "baseSeverity": "HIGH",
          "confidentialityImpact": "HIGH",
          "integrityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "scope": "UNCHANGED",
          "userInteraction": "NONE",
          "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "version": "3.0"
        },
        "exploitabilityScore": 1.8,
        "impactScore": 5.9,
        "source": "nvd@nist.gov",
        "type": "Primary"
      }
    ]
  },
  "published": "2016-11-08T20:59:15.710",
  "references": [
    {
      "source": "psirt@nvidia.com",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "url": "http://nvidia.custhelp.com/app/answers/detail/a_id/4246"
    },
    {
      "source": "psirt@nvidia.com",
      "url": "http://www.securityfocus.com/bid/94177"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "url": "http://nvidia.custhelp.com/app/answers/detail/a_id/4246"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.securityfocus.com/bid/94177"
    }
  ],
  "sourceIdentifier": "psirt@nvidia.com",
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ],
      "source": "nvd@nist.gov",
      "type": "Primary"
    }
  ]
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…