{"api_version":"1","generated_at":"2026-07-23T20:56:17+00:00","cve":"CVE-2011-0636","urls":{"html":"https://cve.report/CVE-2011-0636","api":"https://cve.report/api/cve/CVE-2011-0636.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2011-0636","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2011-0636"},"summary":{"title":"CVE-2011-0636","description":"The (1) cudaHostAlloc and (2) cuMemHostAlloc functions in the NVIDIA CUDA Toolkit 3.2 developer drivers for Linux 260.19.26, and possibly other versions, do not initialize pinned memory, which allows local users to read potentially sensitive memory, such as file fragments during read or write operations.","state":"PUBLISHED","assigner":"mitre","published_at":"2011-01-22 22:00:07","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-200","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.1","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://forums.nvidia.com/index.php?showtopic=190303","name":"http://forums.nvidia.com/index.php?showtopic=190303","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Serious security issue with CUDA on Linux - NVIDIA Forums","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/515591/100/0/threaded","name":"http://www.securityfocus.com/archive/1/515591/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://classic.chem.msu.su/cgi-bin/ceilidh.exe/gran/gamess/forum/?C35e9ea936bHW-7676-1022+00.htm","name":"http://classic.chem.msu.su/cgi-bin/ceilidh.exe/gran/gamess/forum/?C35e9ea936bHW-7676-1022+00.htm","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Ceilidh ... Re: Firefly with CUDA-enabled MP4 code is now available for Linux - follow-up on CUDA security hole","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64710","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64710","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://classic.chem.msu.su/cgi-bin/ceilidh.exe/gran/gamess/forum/?C35e9ea936bHW-7677-1391+00.htm","name":"http://classic.chem.msu.su/cgi-bin/ceilidh.exe/gran/gamess/forum/?C35e9ea936bHW-7677-1391+00.htm","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Ceilidh ... Re^2: Firefly with CUDA-enabled MP4 code is now available for Linux - follow-up on CUDA security hole","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://classic.chem.msu.su/cgi-bin/ceilidh.exe/gran/gamess/forum/?C35e9ea936bHW-7681-487+00.htm","name":"http://classic.chem.msu.su/cgi-bin/ceilidh.exe/gran/gamess/forum/?C35e9ea936bHW-7681-487+00.htm","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Ceilidh ... Re^3: Firefly with CUDA-enabled MP4 code is now available for Linux - follow-up on CUDA security hole","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://classic.chem.msu.su/cgi-bin/ceilidh.exe/gran/gamess/forum/?C35e9ea936bHW-7675-1380-00.htm","name":"http://classic.chem.msu.su/cgi-bin/ceilidh.exe/gran/gamess/forum/?C35e9ea936bHW-7675-1380-00.htm","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Ceilidh ... Firefly with CUDA-enabled MP4 code is now available for Linux","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/516121/100/0/threaded","name":"http://www.securityfocus.com/archive/1/516121/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/45717","name":"http://www.securityfocus.com/bid/45717","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"NVIDIA CUDA Driver For Linux Local Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://osvdb.org/70420","name":"http://osvdb.org/70420","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/42859","name":"http://secunia.com/advisories/42859","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"NVIDIA CUDA Toolkit / Graphics Drivers for Linux Memory Disclosure - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1024962","name":"http://www.securitytracker.com/id?1024962","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"NVIDIA CUDA Driver Toolkit Discloses Information to Local Users - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2011-0636","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2011-0636","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2011","cve_id":"636","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nvidia","cpe5":"cuda_toolkit","cpe6":"3.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T21:58:25.963Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"45717","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/45717"},{"name":"cuda-toolkit-cudahostalloc-info-disc(64710)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64710"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://classic.chem.msu.su/cgi-bin/ceilidh.exe/gran/gamess/forum/?C35e9ea936bHW-7676-1022+00.htm"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://classic.chem.msu.su/cgi-bin/ceilidh.exe/gran/gamess/forum/?C35e9ea936bHW-7677-1391+00.htm"},{"name":"70420","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/70420"},{"name":"20110107 CUDA drivers/Linux security hole","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/515591/100/0/threaded"},{"name":"42859","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/42859"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://classic.chem.msu.su/cgi-bin/ceilidh.exe/gran/gamess/forum/?C35e9ea936bHW-7681-487+00.htm"},{"name":"1024962","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1024962"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://classic.chem.msu.su/cgi-bin/ceilidh.exe/gran/gamess/forum/?C35e9ea936bHW-7675-1380-00.htm"},{"name":"20110201 fix for Nvidia CUDA drivers security breach","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/516121/100/0/threaded"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://forums.nvidia.com/index.php?showtopic=190303"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2011-01-05T00:00:00.000Z","descriptions":[{"lang":"en","value":"The (1) cudaHostAlloc and (2) cuMemHostAlloc functions in the NVIDIA CUDA Toolkit 3.2 developer drivers for Linux 260.19.26, and possibly other versions, do not initialize pinned memory, which allows local users to read potentially sensitive memory, such as file fragments during read or write operations."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-09T18:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"45717","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/45717"},{"name":"cuda-toolkit-cudahostalloc-info-disc(64710)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64710"},{"tags":["x_refsource_MISC"],"url":"http://classic.chem.msu.su/cgi-bin/ceilidh.exe/gran/gamess/forum/?C35e9ea936bHW-7676-1022+00.htm"},{"tags":["x_refsource_MISC"],"url":"http://classic.chem.msu.su/cgi-bin/ceilidh.exe/gran/gamess/forum/?C35e9ea936bHW-7677-1391+00.htm"},{"name":"70420","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/70420"},{"name":"20110107 CUDA drivers/Linux security hole","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/515591/100/0/threaded"},{"name":"42859","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/42859"},{"tags":["x_refsource_MISC"],"url":"http://classic.chem.msu.su/cgi-bin/ceilidh.exe/gran/gamess/forum/?C35e9ea936bHW-7681-487+00.htm"},{"name":"1024962","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1024962"},{"tags":["x_refsource_MISC"],"url":"http://classic.chem.msu.su/cgi-bin/ceilidh.exe/gran/gamess/forum/?C35e9ea936bHW-7675-1380-00.htm"},{"name":"20110201 fix for Nvidia CUDA drivers security breach","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/516121/100/0/threaded"},{"tags":["x_refsource_CONFIRM"],"url":"http://forums.nvidia.com/index.php?showtopic=190303"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2011-0636","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The (1) cudaHostAlloc and (2) cuMemHostAlloc functions in the NVIDIA CUDA Toolkit 3.2 developer drivers for Linux 260.19.26, and possibly other versions, do not initialize pinned memory, which allows local users to read potentially sensitive memory, such as file fragments during read or write operations."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"45717","refsource":"BID","url":"http://www.securityfocus.com/bid/45717"},{"name":"cuda-toolkit-cudahostalloc-info-disc(64710)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/64710"},{"name":"http://classic.chem.msu.su/cgi-bin/ceilidh.exe/gran/gamess/forum/?C35e9ea936bHW-7676-1022+00.htm","refsource":"MISC","url":"http://classic.chem.msu.su/cgi-bin/ceilidh.exe/gran/gamess/forum/?C35e9ea936bHW-7676-1022+00.htm"},{"name":"http://classic.chem.msu.su/cgi-bin/ceilidh.exe/gran/gamess/forum/?C35e9ea936bHW-7677-1391+00.htm","refsource":"MISC","url":"http://classic.chem.msu.su/cgi-bin/ceilidh.exe/gran/gamess/forum/?C35e9ea936bHW-7677-1391+00.htm"},{"name":"70420","refsource":"OSVDB","url":"http://osvdb.org/70420"},{"name":"20110107 CUDA drivers/Linux security hole","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/515591/100/0/threaded"},{"name":"42859","refsource":"SECUNIA","url":"http://secunia.com/advisories/42859"},{"name":"http://classic.chem.msu.su/cgi-bin/ceilidh.exe/gran/gamess/forum/?C35e9ea936bHW-7681-487+00.htm","refsource":"MISC","url":"http://classic.chem.msu.su/cgi-bin/ceilidh.exe/gran/gamess/forum/?C35e9ea936bHW-7681-487+00.htm"},{"name":"1024962","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1024962"},{"name":"http://classic.chem.msu.su/cgi-bin/ceilidh.exe/gran/gamess/forum/?C35e9ea936bHW-7675-1380-00.htm","refsource":"MISC","url":"http://classic.chem.msu.su/cgi-bin/ceilidh.exe/gran/gamess/forum/?C35e9ea936bHW-7675-1380-00.htm"},{"name":"20110201 fix for Nvidia CUDA drivers security breach","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/516121/100/0/threaded"},{"name":"http://forums.nvidia.com/index.php?showtopic=190303","refsource":"CONFIRM","url":"http://forums.nvidia.com/index.php?showtopic=190303"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2011-0636","datePublished":"2011-01-22T21:00:00.000Z","dateReserved":"2011-01-22T00:00:00.000Z","dateUpdated":"2024-08-06T21:58:25.963Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2011-01-22 22:00:07","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-200","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:nvidia:cuda_toolkit:3.2:*:*:*:*:*:*:*","matchCriteriaId":"D847561A-6054-405E-8AF8-4C10C2B62F65"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2011","CveId":"636","Ordinal":"1","Title":"CVE-2011-0636","CVE":"CVE-2011-0636","Year":"2011"},"notes":[{"CveYear":"2011","CveId":"636","Ordinal":"1","NoteData":"The (1) cudaHostAlloc and (2) cuMemHostAlloc functions in the NVIDIA CUDA Toolkit 3.2 developer drivers for Linux 260.19.26, and possibly other versions, do not initialize pinned memory, which allows local users to read potentially sensitive memory, such as file fragments during read or write operations.","Type":"Description","Title":"CVE-2011-0636"},{"CveYear":"2011","CveId":"636","Ordinal":"2","NoteData":"2011-01-22","Type":"Other","Title":"Published"},{"CveYear":"2011","CveId":"636","Ordinal":"3","NoteData":"2018-10-09","Type":"Other","Title":"Modified"}]}}}