CVE-2021-1056
Publication date 7 January 2021
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
NVIDIA GPU Display Driver for Linux, all versions, contains a vulnerability in the kernel mode layer (nvidia.ko) in which it does not completely honor operating system file system permissions to provide GPU device-level isolation, which may lead to denial of service or information disclosure.
From the Ubuntu Security Team
Xinyuan Lyu discovered that the NVIDIA GPU display driver for the Linux kernel did not properly restrict device-level GPU isolation. A local attacker could use this to cause a denial of service or possibly expose sensitive information.
Status
Package | Ubuntu Release | Status |
---|---|---|
nvidia-graphics-drivers-390 | ||
20.04 LTS focal |
Fixed 390.141-0ubuntu0.20.04.1
|
|
18.04 LTS bionic |
Fixed 390.141-0ubuntu0.18.04.1
|
|
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
nvidia-graphics-drivers-418-server | ||
20.04 LTS focal |
Fixed 418.181.07-0ubuntu0.20.04.1
|
|
18.04 LTS bionic |
Fixed 418.181.07-0ubuntu0.18.04.1
|
|
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
nvidia-graphics-drivers-440-server | ||
20.04 LTS focal | Ignored superseded by 450-server | |
18.04 LTS bionic | Ignored superseded by 450-server | |
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
nvidia-graphics-drivers-450 | ||
20.04 LTS focal |
Fixed 450.102.04-0ubuntu0.20.04.1
|
|
18.04 LTS bionic |
Fixed 450.102.04-0ubuntu0.18.04.1
|
|
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
nvidia-graphics-drivers-450-server | ||
20.04 LTS focal |
Fixed 450.102.04-0ubuntu0.20.04.1
|
|
18.04 LTS bionic |
Fixed 450.102.04-0ubuntu0.18.04.1
|
|
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
nvidia-graphics-drivers-455 | ||
20.04 LTS focal | Ignored not available | |
18.04 LTS bionic | Ignored not available | |
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release | |
nvidia-graphics-drivers-460 | ||
20.04 LTS focal |
Fixed 460.32.03-0ubuntu0.20.04.1
|
|
18.04 LTS bionic |
Fixed 460.32.03-0ubuntu0.18.04.1
|
|
16.04 LTS xenial | Not in release | |
14.04 LTS trusty | Not in release |
Notes
alexmurray
CVE-2021-1052, CVE-2021-1053, and CVE-2021-1056 affect the following NVIDIA driver series: 450, 455, 418-server, 440-server, 450-server
sbeattie
NVIDIA series 455 are superseded by the 460 series. NVIDIA series 440-server are superseded by 450-server.
Severity score breakdown
Parameter | Value |
---|---|
Base score | 7.1 · High |
Attack vector | Local |
Attack complexity | Low |
Privileges required | Low |
User interaction | None |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | None |
Availability impact | High |
Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H |
References
Related Ubuntu Security Notices (USN)
- USN-4689-1
- NVIDIA graphics drivers vulnerabilities
- 11 January 2021
- USN-4689-2
- Linux kernel vulnerabilities
- 11 January 2021