Skip to content
-
Subscribe to our newsletter & never miss our best posts. Subscribe Now!
  • https://www.facebook.com/
  • https://twitter.com/
  • https://t.me/
  • https://www.instagram.com/
  • https://youtube.com/
Excellentpix Excellentpix

Intelligence Redefined

Excellentpix Excellentpix

Intelligence Redefined

  • Green Energy
  • Tech News
  • Gadget
  • Smartphone
  • Laptop
  • PC
  • About Us
    • Advertise Here
    • Contact Us
    • Privacy Policy
    • Sitemap
  • Green Energy
  • Tech News
  • Gadget
  • Smartphone
  • Laptop
  • PC
  • About Us
    • Advertise Here
    • Contact Us
    • Privacy Policy
    • Sitemap
Subscribe
Close

Search

Nvidia patches 29 GPU driver bugs • The Register
PC

Nvidia patches 29 GPU driver bugs • The Register

By Maria H. Gray
June 15, 2023 3 Min Read
0

Nvidia fixed more than two dozen security flaws in its GPU display driver, the most severe of which could allow an unprivileged user to modify files, and then escalate privileges, execute code, tamper with or steal data, or even take over your device.

In total, the chipmaker patched 29 vulnerabilities affecting Windows and Linux products, including 10 high-severity bugs.

Nvidia doesn’t publish a ton of technical information about the flaws to ensure that customers can patch their systems before miscreants find exploit these vulnerabilities — hopefully – but here’s what we do know about the security issues.

The most severe of the bunch, tracked as CVE-2022-34669, affects the Windows version of the GPU display driver and received a CVSS score of 8.8. 

According to Nvidia, this vulnerability could allow “an unprivileged regular user [to] access or modify system files or other files that are critical to the application.” Successful exploitation could lead to code execution, denial of service, escalation of privileges, information disclosure or data tampering, the advisory noted.

Another high-severity flaw (CVE-2022-34671) that also affects the Windows product and received an 8.5 CVSS rating exists in the GPU display driver user mode layer. This one could allow an unprivileged user to cause an out-of-bounds write, also leading to code execution, denial of service, escalation of privileges, information disclosure or data tampering, according to Nvidia.

Four others received 7.8 CVSS scores. They are:

CVE-2022-34672, a vulnerability in the control panel for Windows that could allow an unauthorized user to gain privileges, read sensitive information and execute commands.

CVE-2022-34670, which is found in the kernel mode layer handler of the GPU display driver for Linux. “An unprivileged regular user can cause truncation errors when casting a primitive to a primitive of smaller size causes data to be lost in the conversion, which may lead to denial of service or information disclosure,” the security bulletin warned.

CVE-2022-42260, also in the Linux version of the GPU display driver. This one is due to improper preservation of permissions in the D-Bus configuration file. An unauthorized user in the guest VM could exploit this bug on protected D-Bus endpoints, leading to code execution, denial of service, escalation of privileges, information disclosure or data tampering, the chipmaker said.

Finally, CVE-2022-42261, a flaw in the virtual GPU management software, doesn’t properly validate an input index, leading to buffer overrun, causing data tampering, information disclosure or denial of service.

The 29 bugs detailed in the security bulletin affect several different Nvidia software products: GeForce, Studio, Nvidia RTX, Quadro, NVS, and Tesla running on Windows systems. Plus GeForce, Nvidia RTX, Quadro, NVS and Tesla on Linux-based devices. 

Nvidia didn’t immediately respond to The Register‘s inquiry about whether it’s aware of these vulnerabilities being exploited in the wild, but we’ll update this story as we learn more. ®

Tags:

GPUNvidiaRegister
Author

Maria H. Gray

Follow Me
Other Articles
Apple’s AR/VR Headset Might Be One Step Closer to Release – Review Geek
Previous

Apple’s AR/VR Headset Might Be One Step Closer to Release – Review Geek

Next

Review: Appsmith shines for low-code development on a budget

No Comment! Be the first one.

Leave a Reply Cancel reply

You must be logged in to post a comment.

October 2026
M T W T F S S
 1234
567891011
12131415161718
19202122232425
262728293031  
« Sep    

Archives

Categories

  • Car
  • Entertainment
  • Gadget
  • Games
  • general
  • Green Energy
  • internet marketing
  • IT Solutions
  • Laptop
  • Lifestyle
  • PC
  • Property
  • Real estate
  • SEO
  • Smartphone
  • Software Company
  • Start Up
  • Tech News
  • Technology
  • uncategorized

Recent Posts

  • Nemanex en gouttes : comment lire un avis avant d’essayer un complément alimentaire
  • Casino en ligne — Étapes d’un dépôt et d’un retrait: Spinboss
  • Nettikasino — Flamez: Talletus- ja nostojen vaiheet: Pelit ja talletukset: käytännöllinen katsaus olennaisiin tietoihin
  • HIPAA EDI Transactions Explained: 834, 835, 837, 270/271, 276/277, 278 and 820
  • AI-Powered Phishing Is Getting Better: How Staff Training Needs to Change in 2026

fiver

Fiverr Logo

Tags

Amazon Android announces app Apple Big Black Buy Car coming deals Electric Galaxy game games gaming Google Heres Hunter iPhone laptop Laptops launch Market Microsoft news phone Pro Release Review sale Sales Samsung Series Smartphone software startup startups Stock tech Tesla top Windows Xbox year

PHP 2026

statutesaga
homeisallabout

BL

excellentpix.com

WhatsApp us