4 ms·
https://nvidia.custhelp.com/app/answers/detail/a_id/5586 https://nvidia.custhelp.com/app/answers/detail/a_id/5586 >NVIDIA GPU Display Driver for Windows and Li
by DowsingSpoon 2y ago
https://nvidia.custhelp.com/app/answers/detail/a_id/5586 https://nvidia.custhelp.com/app/answers/detail/a_id/5586
>NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability which could allow a privileged attacker to escalate permissions. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering
What does “privileged attacker” mean on Linux? In my mind, “privileged” would mean they already have root, but in that case there’s nothing to escalate, right?
- deleted 2y ago[deleted]
- deleted 2y ago[deleted]
- helsinkiandrew 2y agoPresumably it needs to be run by someone who already has access to the computer and gives them (or a program executed by them) root/escalated privileges. Although that might include running code from a webpage etc.
- hiddencost 2y agoIncluding an advertiser on a webpage.
- l33tman 2y agoWondering the same. The same column lists a bunch of Windows-only CVEs where an unprivileged user can do stuff, so there has to be some difference between those (CVE‑2024‑0117 - CVE‑2024‑0121) and the headliner CVE‑2024‑0126 They mention hypervisor breaches further below, so could the CVE 0126 imply that a local root user on a shared GPU machine of some sort can break out of the virtualization?
- formerly_proven 2y agoThat one is probably only an issue for folks who care about the root/kernel distinction, but there’s a bunch of buffer issues with the user mode component (this runs inside your process when you use graphics APIs). Not enough details, but that could be potentially exploitable from e.g. WebGL/WebGPU
- mmsc 2y agoa member of the 'video' group