1 |
type: security |
2 |
subject: Updated nvidia390 packages fix security vulnerabilities |
3 |
CVE: |
4 |
- CVE‑2021‑1052 |
5 |
- CVE‑2021‑1053 |
6 |
- CVE‑2021‑1056 |
7 |
src: |
8 |
7: |
9 |
nonfree: |
10 |
- nvidia390-390.141-1.mga7.nonfree |
11 |
description: | |
12 |
NVIDIA GPU Display Driver Linux contains a vulnerability in the kernel mode |
13 |
layer (nvidia.ko) IOCTL in which user-mode clients can access legacy |
14 |
privileged APIs, which may lead to denial of service, escalation of privileges, |
15 |
and information disclosure (CVE‑2021‑1052). |
16 |
|
17 |
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel |
18 |
mode layer (nvidia.ko) IOCTL in which improper validation of a user pointer |
19 |
may lead to denial of service (CVE‑2021‑1053). |
20 |
|
21 |
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel |
22 |
mode layer (nvidia.ko) in which it does not completely honor operating system |
23 |
file system permissions to provide GPU device-level isolation, which may |
24 |
lead to denial of service or information disclosure (CVE‑2021‑1056). |
25 |
references: |
26 |
- https://bugs.mageia.org/show_bug.cgi?id=28050 |
27 |
- https://nvidia.custhelp.com/app/answers/detail/a_id/5142/~/security-bulletin%3A-nvidia-gpu-display-driver---january-2021 |
28 |
ID: MGASA-2021-0026 |