CVE-2014-8298
Summary
| CVE | CVE-2014-8298 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-12-10 15:59:16 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The NVIDIA Linux Discrete GPU drivers before R304.125, R331.x before R331.113, R340.x before R340.65, R343.x before R343.36, and R346.x before R346.22, Linux for Tegra (L4T) driver before R21.2, and Chrome OS driver before R40 allows remote attackers to cause a denial of service (segmentation fault and X server crash) or possibly execute arbitrary code via a crafted GLX indirect rendering protocol request. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Nvidia | Gpu Driver | r304.125 | All | All | All |
| Application | Nvidia | Gpu Driver | r331.00 | All | All | All |
| Application | Nvidia | Gpu Driver | r331.112 | All | All | All |
| Application | Nvidia | Gpu Driver | r340.00 | All | All | All |
| Application | Nvidia | Gpu Driver | r340.65 | All | All | All |
| Application | Nvidia | Gpu Driver | r343.00 | All | All | All |
| Application | Nvidia | Gpu Driver | r343.36 | All | All | All |
| Application | Nvidia | Gpu Driver | r346.00 | All | All | All |
| Application | Nvidia | Gpu Driver | r346.22 | All | All | All |
| Application | Nvidia | Gpu Driver | All | All | All | All |
| Application | Nvidia | Gpu Driver | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Oracle Bulletin Board Update - January 2015 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| CVE-2014-8298: GLX-INDIRECT (Including CVE-2014-8093, CVE-2014-8098) | af854a3a-2127-422b-91ae-364da2661108 | nvidia.custhelp.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.