// For flags

CVE-2018-3979

 

Severity Score

6.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

A remote denial-of-service vulnerability exists in the way the Nouveau Display Driver (the default Ubuntu Nvidia display driver) handles GPU shader execution. A specially crafted pixel shader can cause remote denial-of-service issues. An attacker can provide a specially crafted website to trigger this vulnerability. This vulnerability can be triggered remotely after the user visits a malformed website. No further user interaction is required. Vulnerable versions include Ubuntu 18.04 LTS (linux 4.15.0-29-generic x86_64), Nouveau Display Driver NV117 (vermagic: 4.15.0-29-generic SMP mod_unload).

Existe una vulnerabilidad de denegación de servicio (DoS) remota en la manera en la que el controlador Nouveau Display (el controlador de visualización de Ubuntu Nvidia por defecto) gestiona la ejecución del shader de la GPU. Un shader de píxeles especialmente manipulado puede provocar fallos de denegación de servicio (DoS) remota. Un atacante puede proporcionar una imagen especialmente manipulada para desencadenar esta vulnerabilidad. Esta vulnerabilidad puede desencadenarse de manera remota después de que el usuario visita un sitio web mal formado. No se requiere otra interacción del usuario. Las versiones vulnerables incluyen la 18.04 LTS de Ubuntu (linux 4.15.0-29-generic x86_64) y la NV117 del controlador Nouveau Display (vermagic: 4.15.0-29-generic SMP mod_unload).

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-01-02 CVE Reserved
  • 2019-04-01 CVE Published
  • 2023-07-08 EPSS Updated
  • 2024-08-05 CVE Updated
  • 2024-08-05 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-400: Uncontrolled Resource Consumption
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Nvidia
Search vendor "Nvidia"
Geforce Gtx 745 Firmware
Search vendor "Nvidia" for product "Geforce Gtx 745 Firmware"
--
Affected
in Nvidia
Search vendor "Nvidia"
Geforce Gtx 745
Search vendor "Nvidia" for product "Geforce Gtx 745"
--
Safe
Nvidia
Search vendor "Nvidia"
Geforce Gtx 750 Firmware
Search vendor "Nvidia" for product "Geforce Gtx 750 Firmware"
--
Affected
in Nvidia
Search vendor "Nvidia"
Geforce Gtx 750
Search vendor "Nvidia" for product "Geforce Gtx 750"
--
Safe
Nvidia
Search vendor "Nvidia"
Geforce Gtx 750 Ti Firmware
Search vendor "Nvidia" for product "Geforce Gtx 750 Ti Firmware"
--
Affected
in Nvidia
Search vendor "Nvidia"
Geforce Gtx 750 Ti
Search vendor "Nvidia" for product "Geforce Gtx 750 Ti"
--
Safe
Nvidia
Search vendor "Nvidia"
Geforce Gtx 840m Firmware
Search vendor "Nvidia" for product "Geforce Gtx 840m Firmware"
--
Affected
in Nvidia
Search vendor "Nvidia"
Geforce Gtx 840m
Search vendor "Nvidia" for product "Geforce Gtx 840m"
--
Safe
Nvidia
Search vendor "Nvidia"
Geforce Gtx 845m Firmware
Search vendor "Nvidia" for product "Geforce Gtx 845m Firmware"
--
Affected
in Nvidia
Search vendor "Nvidia"
Geforce Gtx 845m
Search vendor "Nvidia" for product "Geforce Gtx 845m"
--
Safe
Nvidia
Search vendor "Nvidia"
Geforce Gtx 850m Firmware
Search vendor "Nvidia" for product "Geforce Gtx 850m Firmware"
--
Affected
in Nvidia
Search vendor "Nvidia"
Geforce Gtx 850m
Search vendor "Nvidia" for product "Geforce Gtx 850m"
--
Safe
Nvidia
Search vendor "Nvidia"
Geforce Gtx 860m Firmware
Search vendor "Nvidia" for product "Geforce Gtx 860m Firmware"
--
Affected
in Nvidia
Search vendor "Nvidia"
Geforce Gtx 860m
Search vendor "Nvidia" for product "Geforce Gtx 860m"
--
Safe
Nvidia
Search vendor "Nvidia"
Geforce Gtx 950m Firmware
Search vendor "Nvidia" for product "Geforce Gtx 950m Firmware"
--
Affected
in Nvidia
Search vendor "Nvidia"
Geforce Gtx 950m
Search vendor "Nvidia" for product "Geforce Gtx 950m"
--
Safe
Nvidia
Search vendor "Nvidia"
Geforce Gtx 960m Firmware
Search vendor "Nvidia" for product "Geforce Gtx 960m Firmware"
--
Affected
in Nvidia
Search vendor "Nvidia"
Geforce Gtx 960m
Search vendor "Nvidia" for product "Geforce Gtx 960m"
--
Safe
Nvidia
Search vendor "Nvidia"
Quadro K620 Firmware
Search vendor "Nvidia" for product "Quadro K620 Firmware"
--
Affected
in Nvidia
Search vendor "Nvidia"
Quadro K620
Search vendor "Nvidia" for product "Quadro K620"
--
Safe
Nvidia
Search vendor "Nvidia"
Quadro K1200 Firmware
Search vendor "Nvidia" for product "Quadro K1200 Firmware"
--
Affected
in Nvidia
Search vendor "Nvidia"
Quadro K1200
Search vendor "Nvidia" for product "Quadro K1200"
--
Safe
Nvidia
Search vendor "Nvidia"
Quadro K2200 Firmware
Search vendor "Nvidia" for product "Quadro K2200 Firmware"
--
Affected
in Nvidia
Search vendor "Nvidia"
Quadro K2200
Search vendor "Nvidia" for product "Quadro K2200"
--
Safe
Nvidia
Search vendor "Nvidia"
Quadro M1000m Firmware
Search vendor "Nvidia" for product "Quadro M1000m Firmware"
--
Affected
in Nvidia
Search vendor "Nvidia"
Quadro M1000m
Search vendor "Nvidia" for product "Quadro M1000m"
--
Safe
Nvidia
Search vendor "Nvidia"
Quadro M1200m Firmware
Search vendor "Nvidia" for product "Quadro M1200m Firmware"
--
Affected
in Nvidia
Search vendor "Nvidia"
Quadro M1200m
Search vendor "Nvidia" for product "Quadro M1200m"
--
Safe
Nvidia
Search vendor "Nvidia"
Grid M30 Firmware
Search vendor "Nvidia" for product "Grid M30 Firmware"
--
Affected
in Nvidia
Search vendor "Nvidia"
Grid M30
Search vendor "Nvidia" for product "Grid M30"
--
Safe
Nvidia
Search vendor "Nvidia"
Grid M40 Firmware
Search vendor "Nvidia" for product "Grid M40 Firmware"
--
Affected
in Nvidia
Search vendor "Nvidia"
Grid M40
Search vendor "Nvidia" for product "Grid M40"
--
Safe
Canonical
Search vendor "Canonical"
Ubuntu Linux
Search vendor "Canonical" for product "Ubuntu Linux"
18.04
Search vendor "Canonical" for product "Ubuntu Linux" and version "18.04"
lts
Affected