Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 351702 (CVE-2011-0636) - <dev-util/nvidia-cuda-toolkit-4.0: memory disclosure (CVE-2011-0636)
Summary: <dev-util/nvidia-cuda-toolkit-4.0: memory disclosure (CVE-2011-0636)
Status: RESOLVED FIXED
Alias: CVE-2011-0636
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/42859/
Whiteboard: B4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2011-01-14 21:25 UTC by Paweł Hajdan, Jr. (RETIRED)
Modified: 2013-04-01 14:33 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2011-01-14 21:25:36 UTC
Two vulnerabilities have been reported in the NVIDIA CUDA Toolkit Developer Drivers for Linux, which can be exploited by malicious, local users to disclose potentially sensitive information.

The vulnerabilities are caused due to the "cudaHostAlloc()" and "cuMemHostAlloc()" API calls returning uncleared pinned memory, which can be exploited to disclose potentially sensitive memory contents.

The vulnerabilities are reported in NVIDIA CUDA Toolkit 3.2 Developer Drivers for Linux version 260.19.26 (64Bit). Other versions may also be affected.
Comment 1 GLSAMaker/CVETool Bot gentoo-dev 2011-06-24 20:00:55 UTC
CVE-2011-0636 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0636):
  The (1) cudaHostAlloc and (2) cuMemHostAlloc functions in the NVIDIA CUDA
  Toolkit 3.2 developer drivers for Linux 260.19.26, and possibly other
  versions, do not initialize pinned memory, which allows local users to read
  potentially sensitive memory, such as file fragments during read or write
  operations.
Comment 2 Justin Lecher (RETIRED) gentoo-dev 2013-01-14 07:47:32 UTC
All evil versions removed from tree.

+*nvidia-cuda-toolkit-5.0.35 (14 Jan 2013)
+*nvidia-cuda-toolkit-4.2.9-r1 (14 Jan 2013)
+
+  14 Jan 2013; Justin Lecher <jlec@gentoo.org> -nvidia-cuda-toolkit-3.2.ebuild,
+  +nvidia-cuda-toolkit-4.2.9-r1.ebuild, +nvidia-cuda-toolkit-5.0.35.ebuild,
+  +files/cuda-config.in, metadata.xml:
+  Version Bump, #446072 and #451972; fine grad what msg we are showing,
+  #440434; support prefix installations, #405317; drop old, #351702; take the
+  package
+
Comment 3 Sean Amoss (RETIRED) gentoo-dev Security 2013-01-15 21:23:47 UTC
Thanks, everyone.

GLSA vote: no.
Comment 4 Tobias Heinlein (RETIRED) gentoo-dev 2013-04-01 14:33:46 UTC
NO too, closing.