Subject: [ASA-202107-58] nvidia-utils: multiple issues Arch Linux Security Advisory ASA-202107-58 ========================================== Severity: Medium Date : 2021-07-21 CVE-ID : CVE-2021-1093 CVE-2021-1094 CVE-2021-1095 Package : nvidia-utils Type : multiple issues Remote : No Link : https://security.archlinux.org/AVG-2193 Summary ======= The package nvidia-utils before version 470.57.02-1 is vulnerable to multiple issues including denial of service and information disclosure. Resolution ========== Upgrade to 470.57.02-1. # pacman -Syu "nvidia-utils>=470.57.02-1" The problems have been fixed upstream in version 470.57.02. Workaround ========== None. Description =========== - CVE-2021-1093 (denial of service) The NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in firmware where the driver contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary, and may lead to denial of service or system crash. - CVE-2021-1094 (information disclosure) The NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler for DxgkDdiEscape where an out of bounds array access may lead to denial of service or information disclosure. - CVE-2021-1095 (denial of service) The NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handlers for all control calls with embedded parameters where dereferencing an untrusted pointer may lead to denial of service. Impact ====== A local attacker could disclose sensitive memory contents or crash the system through crafted system calls to the graphics driver. References ========== https://nvidia.custhelp.com/app/answers/detail/a_id/5211 https://security.archlinux.org/CVE-2021-1093 https://security.archlinux.org/CVE-2021-1094 https://security.archlinux.org/CVE-2021-1095