HIGH · 7.1

CVE-2021-1056

NVIDIA GPU Display Driver for Linux, all versions, contains a vulnerability in the kernel mode layer (nvidia.ko) in which it does not completely honor operating system file system permissions to provi...

Vulnerability Description

NVIDIA GPU Display Driver for Linux, all versions, contains a vulnerability in the kernel mode layer (nvidia.ko) in which it does not completely honor operating system file system permissions to provide GPU device-level isolation, which may lead to denial of service or information disclosure.

CVSS Score

7.1

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
NvidiaGpu Driver>= 390, < 390.141
LinuxLinux Kernel-
DebianDebian Linux9.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-1056?

CVE-2021-1056 is a vulnerability with a CVSS score of 7.1 (HIGH). NVIDIA GPU Display Driver for Linux, all versions, contains a vulnerability in the kernel mode layer (nvidia.ko) in which it does not completely honor operating system file system permissions to provi...

How severe is CVE-2021-1056?

CVE-2021-1056 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-1056?

Check the references section above for vendor advisories and patch information. Affected products include: Nvidia Gpu Driver, Linux Linux Kernel, Debian Debian Linux.