Cyber Security News

NVIDIA Patch Multiple GPU Display Driver for Windows & Linux

NVIDIA has issued essential security updates for its GPU Display Driver, addressing multiple vulnerabilities affecting Windows and Linux systems.

Users are urged to download and install these updates promptly via the NVIDIA Driver Downloads page or the NVIDIA Licensing Portal for vGPU software and Cloud Gaming updates. 

The vulnerabilities identified by their CVE IDs pose significant security risks, including potential code execution, denial of service, privilege escalation, information disclosure, and data tampering.

National Cybersecurity Awareness Month Cyber Challenges – Test your Skills Now

NVIDIA GPU Display Driver Vulnerabilities:

Below is a detailed table of the vulnerabilities addressed:

CVE IDDescriptionBase ScoreSeverityImpacts
CVE‑2024‑0126Another out-of-bounds read vulnerability in the Windows user mode layer.8.2HighCode execution, denial of service, privilege escalation, info disclosure, data tampering
CVE‑2024‑0117Out-of-bounds read vulnerability in Windows user mode layer.7.8HighCode execution, denial of service, privilege escalation, info disclosure, data tampering
CVE‑2024‑0118Similar out-of-bounds read vulnerability in Windows user mode layer.7.8HighCode execution, denial of service, privilege escalation, info disclosure, data tampering
CVE‑2024‑0119Another out-of-bounds read vulnerability in Windows user mode layer.7.8HighCode execution, denial of service, privilege escalation, info disclosure, data tampering
CVE‑2024‑0120Out-of-bounds read vulnerability in Windows user mode layer.7.8HighCode execution, denial of service, privilege escalation, info disclosure, data tampering
CVE‑2024‑0121Out-of-bounds read vulnerability in Windows user mode layer.7.8HighCode execution, denial of service, privilege escalation, info disclosure, data tampering

NVIDIA vGPU Software Vulnerabilities:

CVE IDDescriptionBase ScoreSeverityImpacts
CVE‑2024‑0127Improper input validation in vGPU Manager for all hypervisors.7.8HighCode execution, privilege escalation, data tampering, denial of service, info disclosure
CVE‑2024‑0128Access to global resources in Virtual GPU Manager by guest OS users.7.1HighPrivilege escalation, information disclosure, and data tampering

These updates are crucial for maintaining system security and protecting sensitive information from potential threats.

NVIDIA recommends all users apply these patches immediately to mitigate risks associated with these vulnerabilities.

Free Webinar on How to Protect Small Businesses Against Advanced Cyberthreats -> Watch Here

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Google Issues Warning on Phishing Campaigns Targeting Higher Education Institutions

Google, in collaboration with its Mandiant Threat Intelligence team, has issued a warning about a…

59 minutes ago

TgToxic Android Malware Updated it’s Features to Steal Login Credentials

The TgToxic Android malware, initially discovered in July 2022, has undergone significant updates, enhancing its…

1 hour ago

Hackers Exploiting Cisco Small Business Routers RCE Vulnerability Deploying Webshell

A critical remote code execution (RCE) vulnerability, CVE-2023-20118, affecting Cisco Small Business Routers, has become…

1 hour ago

Malicious npm Package Targets Developers for Supply Chain Attack

The Socket Research Team has uncovered a malicious npm package@ton-wallet/create designed to steal sensitive cryptocurrency…

2 hours ago

New Auto-Color Malware Attacking Linux Devices to Gain Full Remote Access

Researchers at Palo Alto Networks have identified a new Linux malware, dubbed "Auto-Color," that has…

2 hours ago

Lumma Stealer Malware Delivered Through Weaponized Files Disguised as Videos

The Lumma Stealer malware, a sophisticated infostealer, is being actively distributed through malicious files disguised…

2 hours ago