CVE Vulnerabilities

CVE-2022-34680

Incorrect Conversion between Numeric Types

Published: Dec 30, 2022 | Modified: Oct 19, 2023
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer handler, where an integer truncation can lead to an out-of-bounds read, which may lead to denial of service.

Weakness

When converting from one data type to another, such as long to integer, data can be omitted or translated in a way that produces unexpected values. If the resulting values are used in a sensitive context, then dangerous behaviors may occur.

Affected Software

Name Vendor Start Version End Version
Gpu_display_driver Nvidia 390 (including) 390.157 (excluding)
Gpu_display_driver Nvidia 470 (including) 470.161.03 (excluding)
Gpu_display_driver Nvidia 510 (including) 510.108.03 (excluding)
Gpu_display_driver Nvidia 515 (including) 515.86.01 (excluding)
Gpu_display_driver Nvidia 525 (including) 525.60.11 (excluding)

Potential Mitigations

References