CVE-2022-34684

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an off-by-one error may lead to data tampering or information disclosure.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*
OR cpe:2.3:o:citrix:hypervisor:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_kernel-based_virtual_machine:-:*:*:*:*:*:*:*
cpe:2.3:o:vmware:vsphere:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:nvidia:cloud_gaming:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:a:nvidia:cloud_gaming:*:*:*:*:*:*:*:*
OR cpe:2.3:o:citrix:hypervisor:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_kernel-based_virtual_machine:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
OR cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:linux:*:*
cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:linux:*:*
OR cpe:2.3:a:nvidia:geforce:-:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:nvs:-:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:quadro:-:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:rtx:-:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:tesla:-:*:*:*:*:*:*:*

History

19 Oct 2023, 01:20

Type Values Removed Values Added
References (GENTOO) https://security.gentoo.org/glsa/202310-02 - (GENTOO) https://security.gentoo.org/glsa/202310-02 - Third Party Advisory

03 Oct 2023, 15:15

Type Values Removed Values Added
References
  • (GENTOO) https://security.gentoo.org/glsa/202310-02 -

11 Jan 2023, 20:17

Type Values Removed Values Added
CWE CWE-193
First Time Citrix hypervisor
Nvidia rtx
Linux linux Kernel
Vmware
Nvidia virtual Gpu
Vmware vsphere
Nvidia geforce
Nvidia
Nvidia cloud Gaming
Redhat
Citrix
Linux
Nvidia nvs
Nvidia quadro
Nvidia tesla
Nvidia gpu Display Driver
Redhat enterprise Linux Kernel-based Virtual Machine
CPE cpe:2.3:o:redhat:enterprise_linux_kernel-based_virtual_machine:-:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:tesla:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:linux:*:*
cpe:2.3:o:citrix:hypervisor:-:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:nvs:-:*:*:*:*:*:*:*
cpe:2.3:o:vmware:vsphere:-:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:geforce:-:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:quadro:-:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:rtx:-:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:cloud_gaming:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.1
References (MISC) https://nvidia.custhelp.com/app/answers/detail/a_id/5415 - (MISC) https://nvidia.custhelp.com/app/answers/detail/a_id/5415 - Vendor Advisory

30 Dec 2022, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-12-30 23:15

Updated : 2023-12-10 14:48


NVD link : CVE-2022-34684

Mitre link : CVE-2022-34684

CVE.ORG link : CVE-2022-34684


JSON object : View

Products Affected

nvidia

  • tesla
  • quadro
  • virtual_gpu
  • gpu_display_driver
  • nvs
  • rtx
  • cloud_gaming
  • geforce

redhat

  • enterprise_linux_kernel-based_virtual_machine

linux

  • linux_kernel

vmware

  • vsphere

citrix

  • hypervisor
CWE
CWE-193

Off-by-one Error

CWE-125

Out-of-bounds Read