Nvidia patches serious flaws affecting Windows and Linux machines

(Image credit: Shutterstock.com)

Nvidia has patched a number of security vulnerabilities in its GPU Display and CUDA drivers as well as its Virtual GPU Manager software.

While these flaws require local user access, if exploited they could lead to code execution, denial of service, escalation of privileges and information disclosure on systems running Windows and Linux.

In total, Nvidia patched six vulnerabilities in its GPU Display driver and six vulnerabilities in its vGPU software and in its security bulletin, the company lists the bugs with CVSS V3 base scores ranging from 4.4 to 7.8.

Thankfully though, “the NVIDIA risk assessment is based on an average of risk across a diverse set of installed systems and may not represent the true risk to your local installation”, according to Nvidia's security bulletin. The company also recommends that users consult an IT or security professional to accurately evaluate the risk of their specific system configuration.

Display driver and vGPU vulnerabilities

Nvidia is encouraging users to update their GeForce, Quadro, NVS and Tesla Windows GPU display drivers as well as their Virtual GPU Manager and guest driver software. To do so, you can apply the security updates available on the company's Driver Downloads page.

For users that fail to patch these vulnerabilities manually, Nvidia says that they may also receive the Windows GPU display driver version 451.55, 446.06 and 443.18 from their computer hardware vendors, which also includes its latest security updates.

Enterprise users of Nvidia's vGPU software will need to log in to the Nvidia Enterprise Application Hub to download the updates through the Nvidia Licensing Center.

Via BleepingComputer

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Pro
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Gmail at 20
Your Gmail search results are about to get a huge change - and I'm not sure you're going to be happy with it
A person holding out their hand with a digital AI symbol.
Taking AI to the edge for smaller, smarter, and more secure applications
Image depicting a hand on a scanner
Hackers are targeting unpatched ServiceNow instances that exploit 3 separate year-old vulnerabilities
Someone looking at a marketing graph
Why ‘boring’ tech will be 2025's biggest marketing trend
TinEye website
I like this reverse image search service the most
Latest in News
Seth Milchick and Kier Eagan's animatronic speaking in Severance season 2 episode 10
Apple TV+ announces Severance has been renewed for season 3 after that devastating finale
Spotify's new Concerts Near You playlist feature showing a list of songs by local touring artists
Spotify has launched a new Concerts Near You playlist, making it easier for you to see if your favorite artists are performing in your area
The new Dr. Squatch Call of Duty collection.
Latest Call of Duty collaboration finally lets you rub your body with Soap - and I can't believe I just wrote that
Samsung S95D with peacock feather on screen
Samsung says an OLED-beating new screen tech could come sooner than we thought – but I wouldn't expect it in 4K TVs right away
Nanoleaf PC Screen Mirror Lightstrip set up on gaming PC
This Nanoleaf light strip adds Ambilight-style illumination to your gaming setup – and it's amazingly cheap
The Samsung Galaxy S21 series of phones lying face down.
Samsung announces One UI 7 is coming to older phones after all, but the launch is still a mess