CVE-2016-7389 Information

Share on:

Description

For the NVIDIA Quadro NVS GeForce and Tesla products NVIDIA GPU Display Driver on Linux R304 before 304.132 R340 before 340.98 R367 before 367.55 R361_93 before 361.93.03 and R370 before 370.28 contains a vulnerability in the kernel mode layer (nvidia.ko) handler for mmap() where improper input validation may allow users to gain access to arbitrary physical memory leading to an escalation of privileges.

CVSS Vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Reference

http://nvidia.custhelp.com/app/answers/detail/a_id/4246 http://www.securityfocus.com/bid/94177

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

7.8