CVE
Published Jun 13, 2024
7.8
HIGHCVSS 3.1
EPSS 0.23%
Description
NVIDIA GPU Display Driver for Windows contains a vulnerability where the information from a previous client or another process could be disclosed. A successful exploit of this vulnerability might lead to code execution, information disclosure, or data tampering.
Affected products
-
Affected
- All versions up to and including 17.1, 16.5, 13.10, and the April 2024 release
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| NVIDIA | GPU display driver, vGPU software, and Cloud Gaming | unaffected | Affected
|
Configuration 1
- ≥ 470 · < 475.06
- ≥ 535 · < 538.67
- ≥ 550 · < 552.55
- ≥ 555 · < 555.99
Configuration 2
- < 13.11
- ≥ 14.0 · < 16.6
- ≥ 17.0 · < 17.2
Configuration 3
- < 555.99
-
Affected
- ≥ 0, < 555.99
-
Affected
- ≥ 0, < 552.55
- ≥ 0, < 555.99
-
Affected
- ≥ 0, < 552.55
- ≥ 0, < 555.99
-
Affected
- ≥ 0, < 552.55
- ≥ 0, < 555.99
-
Affected
- ≥ 0, < 555.99
-
Affected
- ≥ 0, < 552.55
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| NVIDIA | Geforce | unknown | Affected
|
| NVIDIA | Nvs Firmware | unknown | Affected
|
| NVIDIA | Quadro Firmware | unknown | Affected
|
| NVIDIA | Rtx | unknown | Affected
|
| NVIDIA | Studio | unknown | Affected
|
| NVIDIA | Tesla | unknown | Affected
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-15890 Advisory
- https://nvidia.custhelp.com/app/answers/detail/a_id/5551 Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-15890 | Advisory | |
| https://nvidia.custhelp.com/app/answers/detail/a_id/5551 | Vendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data