Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-5053


The host memory mapping path feature in the NVIDIA GPU graphics driver R346 before 346.87 and R352 before 352.41 for Linux and R352 before 352.46 for GRID vGPU and vSGA does not properly restrict access to third-party device IO memory, which allows attackers to gain privileges, cause a denial of service (resource consumption), or possibly have unspecified other impact via unknown vectors related to the follow_pfn kernel-mode API call.


Published

2015-11-24T20:59:02.327

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 10.0 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-284

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application nvidia gpu_driver 346.16 Yes
Application nvidia gpu_driver 346.22 Yes
Application nvidia gpu_driver 346.35 Yes
Application nvidia gpu_driver 346.47 Yes
Application nvidia gpu_driver 346.59 Yes
Application nvidia gpu_driver 346.72 Yes
Application nvidia gpu_driver 346.82 Yes
Application nvidia gpu_driver 352.09 Yes
Application nvidia gpu_driver 352.21 Yes
Application nvidia gpu_driver 352.30 Yes
Application nvidia gpu_driver 352.41 Yes

References