FS#52220 - [nvidia-304xx] graphics driver has a security vulnerability

Attached to Project: Arch Linux
Opened by Filip Frackiewicz (notreallyhere) - Wednesday, 21 December 2016, 00:57 GMT
Last edited by Laurent Carlier (lordheavy) - Tuesday, 21 February 2017, 13:47 GMT
Task Type Bug Report
Category Security
Status Closed
Assigned To Levente Polyak (anthraxx)
Architecture All
Severity Low
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 0
Private No

Details

On December 14th, NVIDIA has issued the following security advisory:

CVE-2016-8826

NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys for Windows or nvidia.ko for Linux) where a user can cause a GPU interrupt storm, leading to a denial of service.

Reference: http://nvidia.custhelp.com/app/answers/detail/a_id/4278
This task depends upon

Closed by  Laurent Carlier (lordheavy)
Tuesday, 21 February 2017, 13:47 GMT
Reason for closing:  Fixed
Additional comments about closing:  nvidia-304xx-304.134
Comment by Doug Newgard (Scimmia) - Wednesday, 21 December 2016, 02:34 GMT
Will be moot soon as nvidia-304xx is getting dropped
Comment by Paul Bredbury (brebs) - Wednesday, 21 December 2016, 18:07 GMT
Simply bump the version to 304.134
Comment by Doug Newgard (Scimmia) - Wednesday, 21 December 2016, 18:57 GMT
"Simply bump the version to 304.134"

And who's going to do that? It's an orphaned package that nobody cares about and is going to be removed from the repos shortly.

Loading...