Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 411617 (CVE-2012-0946) - <x11-drivers/nvidia-drivers-295.40 Memory disclosure (CVE-2012-0946)
Summary: <x11-drivers/nvidia-drivers-295.40 Memory disclosure (CVE-2012-0946)
Status: RESOLVED FIXED
Alias: CVE-2012-0946
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2012-04-11 17:56 UTC by Doug Goldstein (RETIRED)
Modified: 2012-06-23 14:43 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Doug Goldstein (RETIRED) gentoo-dev 2012-04-11 17:56:18 UTC
>=x11-driversnvidia-drivers-195.x && <x11-drivers/nvidia-drivers-295.40 are affected by CVE-2012-0946

We mitigate this somewhat by not using NVIDIA's default permissions of 666 but instead use 660 for root:video.
Comment 1 Doug Goldstein (RETIRED) gentoo-dev 2012-04-11 17:59:27 UTC
NVIDIA's response and info: http://nvidia.custhelp.com/app/answers/detail/a_id/3109
Comment 2 Doug Goldstein (RETIRED) gentoo-dev 2012-04-11 18:05:54 UTC
Fixed ebuild is committed to the tree.
Comment 3 Doug Goldstein (RETIRED) gentoo-dev 2012-04-11 20:54:31 UTC
amd64 & x86: please stabilize
Comment 4 Agostino Sarubbo gentoo-dev 2012-04-15 14:04:05 UTC
amd64 stable
Comment 5 Markus Meier gentoo-dev 2012-04-15 16:54:46 UTC
x86 stable, all arches done.
Comment 6 Tim Sammut (RETIRED) gentoo-dev 2012-04-15 18:05:20 UTC
Thanks, everyone. GLSA vote: yes.
Comment 7 juantxorena@gmail.com 2012-04-17 19:49:53 UTC
Please revert:
http://www.nvnews.net/vbulletin/showthread.php?p=2546510#post2546510

In short, graphical corruption, performance issues, crashes and temporary hangs in some cards.
Comment 8 Sean Amoss (RETIRED) gentoo-dev Security 2012-04-18 00:13:53 UTC
(In reply to comment #7)
> Please revert:
> http://www.nvnews.net/vbulletin/showthread.php?p=2546510#post2546510
> 
> In short, graphical corruption, performance issues, crashes and temporary
> hangs in some cards.

Please open a new bug if you have issues with the updated drivers. This bug is regarding the fix of a specific security issue. 


GLSA vote: yes. Creating new GLSA request.
Comment 9 Doug Goldstein (RETIRED) gentoo-dev 2012-04-18 21:25:46 UTC
(In reply to comment #7)
> Please revert:
> http://www.nvnews.net/vbulletin/showthread.php?p=2546510#post2546510
> 
> In short, graphical corruption, performance issues, crashes and temporary
> hangs in some cards.

We do not hold back releases that affect a minority of card users. The NVIDIA drivers are binary only and as such are a best effort. I always recommend people find a release that works well for them on their cards and stick with that release until they have a reason to move forward. Especially if you're a user of older cards which are less tested or supported. The issues you're complaining about affect G80 GPUs and lower. Which include GeForce 6 and GeForce 7 and the initial GeForce 8800GTX cards.

That being said, before people are upset that users of G80 GPUs and older won't have a security fix. This bug affects Gentoo users less than it does other distros. Other distros have had their NVIDIA device nodes set to 666, while Gentoo has always used 660 so it would have required the user give another user account access to the device node before the attack could have worked.
Comment 10 GLSAMaker/CVETool Bot gentoo-dev 2012-04-28 00:42:14 UTC
CVE-2012-0946 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-0946):
  The NVIDIA UNIX driver before 295.40 allows local users to access arbitrary
  memory locations by leveraging GPU device-node read/write privileges.
Comment 11 kisak42 2012-05-12 21:18:21 UTC
Is this regression the same one mentioned in the release notes for nvidia drivers 295.49? (in regards to comment #7)
Comment 12 Doug Goldstein (RETIRED) gentoo-dev 2012-06-19 04:09:26 UTC
security team,

GLSA is out and all old versions are out of the tree. What's left?
Comment 13 GLSAMaker/CVETool Bot gentoo-dev 2012-06-23 14:43:51 UTC
This issue was resolved and addressed in
 GLSA 201206-19 at http://security.gentoo.org/glsa/glsa-201206-19.xml
by GLSA coordinator Sean Amoss (ackle).