Vulnerability Description
The (1) cudaHostAlloc and (2) cuMemHostAlloc functions in the NVIDIA CUDA Toolkit 3.2 developer drivers for Linux 260.19.26, and possibly other versions, do not initialize pinned memory, which allows local users to read potentially sensitive memory, such as file fragments during read or write operations.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nvidia | Cuda Toolkit | 3.2 |
Related Weaknesses (CWE)
References
- http://classic.chem.msu.su/cgi-bin/ceilidh.exe/gran/gamess/forum/?C35e9ea936bHW-
- http://classic.chem.msu.su/cgi-bin/ceilidh.exe/gran/gamess/forum/?C35e9ea936bHW-
- http://classic.chem.msu.su/cgi-bin/ceilidh.exe/gran/gamess/forum/?C35e9ea936bHW-
- http://classic.chem.msu.su/cgi-bin/ceilidh.exe/gran/gamess/forum/?C35e9ea936bHW-
- http://forums.nvidia.com/index.php?showtopic=190303
- http://osvdb.org/70420
- http://secunia.com/advisories/42859Vendor Advisory
- http://www.securityfocus.com/archive/1/515591/100/0/threaded
- http://www.securityfocus.com/archive/1/516121/100/0/threaded
- http://www.securityfocus.com/bid/45717
- http://www.securitytracker.com/id?1024962
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64710
- http://classic.chem.msu.su/cgi-bin/ceilidh.exe/gran/gamess/forum/?C35e9ea936bHW-
- http://classic.chem.msu.su/cgi-bin/ceilidh.exe/gran/gamess/forum/?C35e9ea936bHW-
- http://classic.chem.msu.su/cgi-bin/ceilidh.exe/gran/gamess/forum/?C35e9ea936bHW-
FAQ
What is CVE-2011-0636?
CVE-2011-0636 is a vulnerability with a CVSS score of 2.1 (LOW). The (1) cudaHostAlloc and (2) cuMemHostAlloc functions in the NVIDIA CUDA Toolkit 3.2 developer drivers for Linux 260.19.26, and possibly other versions, do not initialize pinned memory, which allows ...
How severe is CVE-2011-0636?
CVE-2011-0636 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2011-0636?
Check the references section above for vendor advisories and patch information. Affected products include: Nvidia Cuda Toolkit.