Nvidia warns gamers to update their GPU drivers due to severe security problems

Nvidia GPU
(Image credit: Nvidia)

Nvidia has revealed several worrying security issues in its graphics card drivers, and is strongly recommending anyone with one of its GPUs to update its drivers as soon as possible.

As ThreatPost reports, there are five driver security bugs that all score highly in the CVSS vulnerability scale.

The most dangerous of the security bugs that Nvidia has acknowledged appears to be CVE-2021-1074, which is 7.5 out of 10 on the CVSS scale. This bug was found in the Nvidia driver’s installer, and could allow an attacker with physical access to swap out an application resource with malicious files. This could lead to malicious code being run, a denial of service attack, or personal information being stolen.

Meanwhile, CVE-2021-1075 is another high severity bug (scoring 7.3 on the CVSS scale), and resides in the nvlddmkm.sys handler for DxgkDdiEscape. As ThreatPost explains, “the program dereferences a pointer that contains a location for memory that is no longer valid, which may lead to code execution, denial of service, or escalation of privileges.”

CVE-2021-1076 is a medium-severity bug found in the Nvidia GPU Display Driver for Windows and Linux’s kernel mode layer, where malicious users can exploit improper access control to launch denial of service, information theft or data corruption attacks.

CVE-2021-1077 is a medium-level risk in the Windows and Linux drivers, where the driver “uses a reference count to manage a resource that is incorrectly updated, which may lead to denial of service.”

There is also another medium-severity bug, CVE-2021-1078, which was found in all versions of the Windows Nvidia Driver, and again affected the kernel – this time a NULL pointer deference could lead to the PC crashing.

If that’s not bad enough, Nvidia also revealed eight software vulnerabilities in its vGPU software – and these affect workstations and artificial intelligence workloads, and are all medium to high levels of severity.

What you should do

Nvidia has been quick to release driver updates to fix these vulnerabilities, and they should be installed as soon as possible, either though the Nvidia Driver Downloads page or via the GeForce Experience app if you have it installed.

Check out our guide on how to update and install the latest Nvidia graphics drivers for more help.

The amount and severity of these security bugs is certainly troubling, and we’ve contacted Nvidia for comment.

TOPICS
Matt Hanson
Managing Editor, Core Tech

Matt is TechRadar's Managing Editor for Core Tech, looking after computing and mobile technology. Having written for a number of publications such as PC Plus, PC Format, T3 and Linux Format, there's no aspect of technology that Matt isn't passionate about, especially computing and PC gaming. He’s personally reviewed and used most of the laptops in our best laptops guide - and since joining TechRadar in 2014, he's reviewed over 250 laptops and computing accessories personally.

Read more
Digital image of a lock.
Nvidia systems could be facing another worrying security flaw
An Nvidia GeForce RTX 5080 resting on an RTX 5090 on a gray crafting mat.
Nvidia is investigating reports of crashes plaguing RTX 5090 and 5080 GPUs, with possible driver issues maybe hitting RTX 4000 models too
NVIDIA GeForce RTX 50 Series image
Nvidia's 572.70 Game Ready Driver promises a black screen fix - but unless you have an RTX 5070 it's probably best to avoid updating for now
The Nvidia GeForce RTX 5090's power connection port
Nvidia RTX 5090 seemingly has a spanner thrown in the works by new graphics driver, but we should be very careful around reports of ‘bricked’ GPUs
A masculine hand holding the Nvidia GeForce RTX 5070 Ti
New Nvidia drivers should fix a major RTX 50 series GPU issue
Nvidia logo on a dark background
Nvidia's GeForce graphics driver woes continue for some users, despite 572.75 hotfix's overclock and black screen promises
Latest in Security
China
Chinese hackers targeting Juniper Networks routers, so patch now
Google Chrome dark mode
Google updates Chrome extension rules to ban affiliate link injection without user action or benefit
Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard
This worrying botnet targets unsecure TP-Link routers - thousands of devices already hacked
Avast cybersecurity
UK cybersecurity sector could be worth £13bn, research shows
An option to add Ambient Music buttons to the iOS 18.4 Control Center.
Apple fixes dangerous zero-day used in attacks against iPhones and iPads
Trump
Hackers are abusing $TRUMP tokens to lure victims in to new phishing scam
Latest in News
GTA 5
GTA Online publisher Take-Two is gunning for a black market that’s basically heaven for cheaters
The Discovery+ homepage
Discovery+ just got a big update to its streaming app that makes it more like Max – here are 5 great new features to try
Two Android phones on a green and blue background showing Google Messages
Struggling with slow Google Messages photo transfers? Google says new update will make 'noticeable difference'
China
Chinese hackers targeting Juniper Networks routers, so patch now
Google Meet create custom backgrounds
More AI features are coming to Google Workspace
Elayne, Egwene, and Nynaeve dressed regally and on horseback in The Wheel of Time season 3
'There's a reason why we do it': The Wheel of Time showrunner responds to fans who are still upset over the Prime Video show's plot alterations