CVE Vulnerabilities

CVE-2021-1075

NULL Pointer Dereference

Published: Apr 21, 2021 | Modified: Jun 30, 2021
CVSS 3.x
7.3
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H
CVSS 2.x
5.6 MEDIUM
AV:L/AC:L/Au:N/C:N/I:P/A:C
RedHat/V2
RedHat/V3
Ubuntu

NVIDIA Windows GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where the program dereferences a pointer that contains a location for memory that is no longer valid, which may lead to code execution, denial of service, or escalation of privileges. Attacker does not have any control over the information and may conduct limited data modification.

Weakness

A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.

Affected Software

Name Vendor Start Version End Version
Gpu_display_driver Nvidia 418 (including) 427.33 (excluding)
Gpu_display_driver Nvidia 450 (including) 452.96 (excluding)
Gpu_display_driver Nvidia 460 (including) 462.31 (excluding)
Gpu_display_driver Nvidia 465 (including) 466.11 (excluding)

Potential Mitigations

References