Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update: nvidia-drivers #1097

Closed
dongsupark opened this issue Jun 27, 2023 · 2 comments
Closed

update: nvidia-drivers #1097

dongsupark opened this issue Jun 27, 2023 · 2 comments
Labels
advisory security advisory cvss/HIGH > 7 && < 9 assessed CVSS security security concerns

Comments

@dongsupark
Copy link
Member

dongsupark commented Jun 27, 2023

Name: nvidia-drivers
CVEs: CVE-2023-25515, CVE-2023-25516
CVSSs: 7.6, 7.1
Action Needed: update to >= 525.125.06

Summary:

  • CVE-2023-25515: NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where unexpected untrusted data is parsed, which may lead to code execution, denial of service, escalation of privileges, data tampering, or information disclosure.
  • CVE-2023-25516: NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where an unprivileged user can cause an integer overflow, which may lead to information disclosure and denial of service.

refmap.gentoo: https://bugs.gentoo.org/909226

@dongsupark dongsupark added security security concerns advisory security advisory labels Jun 27, 2023
@dongsupark dongsupark moved this from 📝 Needs Triage to 🪵Backlog in Flatcar tactical, release planning, and roadmap Jun 27, 2023
@dongsupark dongsupark moved this from 🪵Backlog to 🌱 Upcoming / Focus in Flatcar tactical, release planning, and roadmap Jul 3, 2023
@tormath1 tormath1 added the cvss/HIGH > 7 && < 9 assessed CVSS label Jul 4, 2023
@sayanchowdhury
Copy link
Member

PR: flatcar/scripts#1121

@dongsupark dongsupark moved this from 🌱 Upcoming / Focus to ⚒️ In Progress in Flatcar tactical, release planning, and roadmap Sep 8, 2023
@dongsupark
Copy link
Member Author

Done in flatcar/scripts#1121.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
advisory security advisory cvss/HIGH > 7 && < 9 assessed CVSS security security concerns
Projects
None yet
Development

No branches or pull requests

3 participants