Vulnerability Description
The NVIDIA display driver R352 before 353.82 and R340 before 341.81 on Windows; R304 before 304.128, R340 before 340.93, and R352 before 352.41 on Linux; and R352 before 352.46 on GRID vGPU and vSGA allows local users to write to an arbitrary kernel memory location and consequently gain privileges via a crafted ioctl call.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nvidia | Gpu Driver | <= 352.30 |
| Nvidia | Display Driver | <= 352.09 |
| Microsoft | Windows | All versions |
Related Weaknesses (CWE)
References
- http://nvidia.custhelp.com/app/answers/detail/a_id/3763/~/cve-2015-5950-memory-cVendor Advisory
- http://www.securitytracker.com/id/1033662
- http://www.ubuntu.com/usn/USN-2747-1
- https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c
- https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c0
- https://support.lenovo.com/us/en/product_security/len_3313
- http://nvidia.custhelp.com/app/answers/detail/a_id/3763/~/cve-2015-5950-memory-cVendor Advisory
- http://www.securitytracker.com/id/1033662
- http://www.ubuntu.com/usn/USN-2747-1
- https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c
- https://h20566.www2.hp.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c0
- https://support.lenovo.com/us/en/product_security/len_3313
FAQ
What is CVE-2015-5950?
CVE-2015-5950 is a vulnerability with a CVSS score of 6.9 (MEDIUM). The NVIDIA display driver R352 before 353.82 and R340 before 341.81 on Windows; R304 before 304.128, R340 before 340.93, and R352 before 352.41 on Linux; and R352 before 352.46 on GRID vGPU and vSGA a...
How severe is CVE-2015-5950?
CVE-2015-5950 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-5950?
Check the references section above for vendor advisories and patch information. Affected products include: Nvidia Gpu Driver, Nvidia Display Driver, Microsoft Windows.