CVE-2015-5053
Summary
| CVE | CVE-2015-5053 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-11-24 20:59:02 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The host memory mapping path feature in the NVIDIA GPU graphics driver R346 before 346.87 and R352 before 352.41 for Linux and R352 before 352.46 for GRID vGPU and vSGA does not properly restrict access to third-party device IO memory, which allows attackers to gain privileges, cause a denial of service (resource consumption), or possibly have unspecified other impact via unknown vectors related to the follow_pfn kernel-mode API call. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:N/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Nvidia | Gpu Driver | 346.16 | All | All | All |
| Application | Nvidia | Gpu Driver | 346.22 | All | All | All |
| Application | Nvidia | Gpu Driver | 346.35 | All | All | All |
| Application | Nvidia | Gpu Driver | 346.47 | All | All | All |
| Application | Nvidia | Gpu Driver | 346.59 | All | All | All |
| Application | Nvidia | Gpu Driver | 346.72 | All | All | All |
| Application | Nvidia | Gpu Driver | 346.82 | All | All | All |
| Application | Nvidia | Gpu Driver | 352.09 | All | All | All |
| Application | Nvidia | Gpu Driver | 352.21 | All | All | All |
| Application | Nvidia | Gpu Driver | 352.30 | All | All | All |
| Application | Nvidia | Gpu Driver | 352.41 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2015-5053: GPU mappings of third-party device IO memory | af854a3a-2127-422b-91ae-364da2661108 | nvidia.custhelp.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.