Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-8298


The NVIDIA Linux Discrete GPU drivers before R304.125, R331.x before R331.113, R340.x before R340.65, R343.x before R343.36, and R346.x before R346.22, Linux for Tegra (L4T) driver before R21.2, and Chrome OS driver before R40 allows remote attackers to cause a denial of service (segmentation fault and X server crash) or possibly execute arbitrary code via a crafted GLX indirect rendering protocol request.


Published

2014-12-10T15:59:16.580

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-19

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application nvidia gpu_driver r304.125 Yes
Application nvidia gpu_driver r331.00 Yes
Application nvidia gpu_driver r331.112 Yes
Application nvidia gpu_driver r340.00 Yes
Application nvidia gpu_driver r340.65 Yes
Application nvidia gpu_driver r343.00 Yes
Application nvidia gpu_driver r343.36 Yes
Application nvidia gpu_driver r346.00 Yes
Application nvidia gpu_driver r346.22 Yes
Application nvidia gpu_driver ≤ r21.2 Yes
Application nvidia gpu_driver ≤ r39 Yes

References