CVE-2018-3979

A remote denial-of-service vulnerability exists in the way the Nouveau Display Driver (the default Ubuntu Nvidia display driver) handles GPU shader execution. A specially crafted pixel shader can cause remote denial-of-service issues. An attacker can provide a specially crafted website to trigger this vulnerability. This vulnerability can be triggered remotely after the user visits a malformed website. No further user interaction is required. Vulnerable versions include Ubuntu 18.04 LTS (linux 4.15.0-29-generic x86_64), Nouveau Display Driver NV117 (vermagic: 4.15.0-29-generic SMP mod_unload).
Configurations

Configuration 1 (hide)

cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:nvidia:geforce_gtx_745_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:geforce_gtx_745:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:nvidia:geforce_gtx_750_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:geforce_gtx_750:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:nvidia:geforce_gtx_750_ti_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:geforce_gtx_750_ti:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:nvidia:geforce_gtx_840m_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:geforce_gtx_840m:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:nvidia:geforce_gtx_845m_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:geforce_gtx_845m:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:nvidia:geforce_gtx_850m_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:geforce_gtx_850m:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:nvidia:geforce_gtx_860m_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:geforce_gtx_860m:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:nvidia:geforce_gtx_950m_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:geforce_gtx_950m:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:nvidia:geforce_gtx_960m_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:geforce_gtx_960m:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:nvidia:quadro_k620_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:quadro_k620:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:nvidia:quadro_k1200_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:quadro_k1200:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:nvidia:quadro_k2200_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:quadro_k2200:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:nvidia:quadro_m1000m_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:quadro_m1000m:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:nvidia:quadro_m1200m_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:quadro_m1200m:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:nvidia:grid_m30_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:grid_m30:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:nvidia:grid_m40_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:grid_m40:-:*:*:*:*:*:*:*

History

21 Nov 2024, 04:06

Type Values Removed Values Added
References () https://talosintelligence.com/vulnerability_reports/TALOS-2018-0647 - Exploit, Third Party Advisory () https://talosintelligence.com/vulnerability_reports/TALOS-2018-0647 - Exploit, Third Party Advisory

Information

Published : 2019-04-01 21:30

Updated : 2024-11-21 04:06


NVD link : CVE-2018-3979

Mitre link : CVE-2018-3979

CVE.ORG link : CVE-2018-3979


JSON object : View

Products Affected

nvidia

  • geforce_gtx_860m_firmware
  • geforce_gtx_850m
  • quadro_m1200m
  • grid_m40_firmware
  • quadro_m1000m_firmware
  • quadro_k620
  • geforce_gtx_950m_firmware
  • quadro_k2200_firmware
  • geforce_gtx_960m_firmware
  • grid_m40
  • geforce_gtx_745_firmware
  • geforce_gtx_860m
  • geforce_gtx_960m
  • grid_m30
  • geforce_gtx_750
  • quadro_k2200
  • grid_m30_firmware
  • geforce_gtx_840m_firmware
  • geforce_gtx_750_ti_firmware
  • geforce_gtx_845m
  • quadro_k1200
  • geforce_gtx_845m_firmware
  • quadro_m1200m_firmware
  • quadro_m1000m
  • quadro_k1200_firmware
  • geforce_gtx_750_firmware
  • geforce_gtx_750_ti
  • geforce_gtx_950m
  • quadro_k620_firmware
  • geforce_gtx_745
  • geforce_gtx_840m
  • geforce_gtx_850m_firmware

canonical

  • ubuntu_linux
CWE
CWE-400

Uncontrolled Resource Consumption