Vulnerability Description
The host memory mapping path feature in the NVIDIA GPU graphics driver R346 before 346.87 and R352 before 352.41 for Linux and R352 before 352.46 for GRID vGPU and vSGA does not properly restrict access to third-party device IO memory, which allows attackers to gain privileges, cause a denial of service (resource consumption), or possibly have unspecified other impact via unknown vectors related to the follow_pfn kernel-mode API call.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nvidia | Gpu Driver | 346.16 |
Related Weaknesses (CWE)
References
- http://nvidia.custhelp.com/app/answers/detail/a_id/3802Vendor Advisory
- http://nvidia.custhelp.com/app/answers/detail/a_id/3802Vendor Advisory
FAQ
What is CVE-2015-5053?
CVE-2015-5053 is a vulnerability with a CVSS score of 10.0 (HIGH). The host memory mapping path feature in the NVIDIA GPU graphics driver R346 before 346.87 and R352 before 352.41 for Linux and R352 before 352.46 for GRID vGPU and vSGA does not properly restrict acce...
How severe is CVE-2015-5053?
CVE-2015-5053 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-5053?
Check the references section above for vendor advisories and patch information. Affected products include: Nvidia Gpu Driver.