Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 678844 (CVE‑2018‑6260)

Summary: <x11-drivers/nvidia-drivers-{390.116,410.104,418.43} - vulnerability that may allow access to application data processed on the GPU through a side channel exposed by the GPU performance counters
Product: Gentoo Security Reporter: Jeroen Roovers (RETIRED) <jer>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal    
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://nvidia.custhelp.com/app/answers/detail/a_id/4772
Whiteboard: A4 [glsa cve]
Package list:
Runtime testing required: ---

Description Jeroen Roovers (RETIRED) gentoo-dev 2019-02-26 16:49:52 UTC
"NVIDIA graphics driver contains a vulnerability that may allow access to application data processed on the GPU through a side channel exposed by the GPU performance counters. Local user access is required. This vulnerability is not a network or remote attack vector."
Comment 1 Larry the Git Cow gentoo-dev 2019-02-26 16:50:28 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=6dcc091f6aa74a598a015d62d9e576d75626f8c6

commit 6dcc091f6aa74a598a015d62d9e576d75626f8c6
Author:     Jeroen Roovers <jer@gentoo.org>
AuthorDate: 2019-02-26 16:46:00 +0000
Commit:     Jeroen Roovers <jer@gentoo.org>
CommitDate: 2019-02-26 16:50:24 +0000

    x11-drivers/nvidia-drivers: Old
    
    Package-Manager: Portage-2.3.62, Repoman-2.3.12
    Bug: https://bugs.gentoo.org/678844
    Signed-off-by: Jeroen Roovers <jer@gentoo.org>

 x11-drivers/nvidia-drivers/Manifest                |  12 -
 .../nvidia-drivers/nvidia-drivers-390.87.ebuild    | 582 --------------------
 .../nvidia-drivers/nvidia-drivers-410.93.ebuild    | 585 ---------------------
 .../nvidia-drivers/nvidia-drivers-418.30.ebuild    | 578 --------------------
 4 files changed, 1757 deletions(-)
Comment 2 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2020-06-27 19:41:36 UTC
Tree clean, too old for GLSA.