Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Artificial Intelligence

Nvidia Patches High-Severity Flaws in Windows, Linux Graphics Drivers

Nvidia rolls out urgent security updates to fix at least 8 high-severity vulnerabilities in GPU drivers for Windows and Linux.

Nvidia patches

Technology giant Nvidia has rolled out urgent security updates to fix at least 8 high-severity vulnerabilities in GPU drivers for Windows and Linux, and in its virtual GPU (vGPU) software.

The company shipped updates for five security defects affecting Nvidia’s graphics drivers for Windows that allow an unprivileged user to cause an out-of-bounds read.

Tracked as CVE‑2024‑0117 to CVE‑2024‑0121, these bugs could be exploited for code execution, escalation of privilege, denial-of-service, information disclosure, and data tampering, Nvidia said in an advisory.

A sixth issue, tracked as CVE‑2024‑0126 and affecting both Windows and Linux GPU drivers from Nvidia, allows a privileged attacker to escalate permissions, with similar consequences as the other five flaws.

Nvidia released software updates for its GeForce, NVIDIA RTX, Quadro, NVS, and Tesla products to resolve these bugs in R565, R560, R555, R550, and R535 Windows driver branches, and in R565, R550, and R535 Linux driver branches.

Nvidia notes that earlier branch software releases might be affected by these vulnerabilities as well and encourages users to update to the latest branch release.

Advertisement. Scroll to continue reading.

The company resolved two additional flaws in the vGPU software, one in the GPU kernel driver of the vGPU Manager (CVE‑2024‑0127) that could allow “a user of the guest OS can cause an improper input validation by compromising the guest OS kernel,” and another in the vGPU Manager itself (CVE‑2024‑0128) “that allows a user of the guest OS to access global resources.”

While both defects could lead to escalation of privilege, information disclosure, and data tampering, the first vulnerability can also be exploited for code execution and denial-of-service.

Nvidia vGPU software versions 17.4 and 16.8 contain patched driver iterations that resolve all the above vulnerabilities. Fixes for these flaws were also included in the October 2024 release of Nvidia Cloud Gaming software.

Users are advised to apply the available patches as soon as possible. Additional information can be found on Nvidia’s product security page.

Related: Code Execution, Data Tampering Flaw in Nvidia NeMo Gen-AI Framework

Related: AMD Says Sinkclose CPU Flaw Only Affects ‘Seriously Breached Systems’

Related: Nvidia Patches High-Severity GPU Driver Vulnerabilities

Related: ‘USB Over Ethernet’ Driver Vulnerabilities Affected Major Cloud Services

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Alex Levinson has been named Executive Director at the National Collegiate Cyber Defense Competition.

Hack The Box has appointed Konstantinos Dolkas as CTO and has promoted Christine Bartlett to CMO.

The Department of Energy has appointed Andrew McClure as Director of the Office of Cybersecurity, Energy Security, and Emergency Response (CESER).

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.