CVE-2011-0636
Summary
| CVE | CVE-2011-0636 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-01-22 22:00:00 UTC |
| Updated | 2018-10-09 19:29:00 UTC |
| Description | The (1) cudaHostAlloc and (2) cuMemHostAlloc functions in the NVIDIA CUDA Toolkit 3.2 developer drivers for Linux 260.19.26, and possibly other versions, do not initialize pinned memory, which allows local users to read potentially sensitive memory, such as file fragments during read or write operations. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Nvidia | Cuda Toolkit | 3.2 | All | All | All |
| Application | Nvidia | Cuda Toolkit | 3.2 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 70420 | OSVDB | osvdb.org | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Ceilidh ... Firefly with CUDA-enabled MP4 code is now available for Linux | MISC | classic.chem.msu.su | |
| Ceilidh ... Re: Firefly with CUDA-enabled MP4 code is now available for Linux - follow-up on CUDA security hole | MISC | classic.chem.msu.su | |
| NVIDIA CUDA Driver Toolkit Discloses Information to Local Users - SecurityTracker | SECTRACK | www.securitytracker.com | |
| Ceilidh ... Re^2: Firefly with CUDA-enabled MP4 code is now available for Linux - follow-up on CUDA security hole | MISC | classic.chem.msu.su | |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| NVIDIA CUDA Toolkit / Graphics Drivers for Linux Memory Disclosure - Secunia.com | SECUNIA | secunia.com | Vendor Advisory |
| SecurityFocus | BUGTRAQ | www.securityfocus.com | |
| NVIDIA CUDA Driver For Linux Local Information Disclosure Vulnerability | BID | www.securityfocus.com | |
| Serious security issue with CUDA on Linux - NVIDIA Forums | CONFIRM | forums.nvidia.com | |
| Ceilidh ... Re^3: Firefly with CUDA-enabled MP4 code is now available for Linux - follow-up on CUDA security hole | MISC | classic.chem.msu.su | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.