Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 884045 (CVE-2022-34670, CVE-2022-34673, CVE-2022-34674, CVE-2022-34676, CVE-2022-34677, CVE-2022-34678, CVE-2022-34679, CVE-2022-34680, CVE-2022-34682, CVE-2022-34684, CVE-2022-42254, CVE-2022-42255, CVE-2022-42256, CVE-2022-42257, CVE-2022-42258, CVE-2022-42259, CVE-2022-42260, CVE-2022-42261, CVE-2022-42263, CVE-2022-42264, CVE-2022-42265) - <x11-drivers/nvidia-drivers-{390.157,470.161.03,510.108.03,515.86.01,525.60.11}: multiple vulnerabilities
Summary: <x11-drivers/nvidia-drivers-{390.157,470.161.03,510.108.03,515.86.01,525.60.1...
Status: RESOLVED FIXED
Alias: CVE-2022-34670, CVE-2022-34673, CVE-2022-34674, CVE-2022-34676, CVE-2022-34677, CVE-2022-34678, CVE-2022-34679, CVE-2022-34680, CVE-2022-34682, CVE-2022-34684, CVE-2022-42254, CVE-2022-42255, CVE-2022-42256, CVE-2022-42257, CVE-2022-42258, CVE-2022-42259, CVE-2022-42260, CVE-2022-42261, CVE-2022-42263, CVE-2022-42264, CVE-2022-42265
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal critical
Assignee: Gentoo Security
URL: https://nvidia.custhelp.com/app/answe...
Whiteboard: A1 [glsa+]
Keywords:
Depends on:
Blocks:
 
Reported: 2022-12-02 17:52 UTC by John Helmert III
Modified: 2023-10-03 12:50 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-12-02 17:52:50 UTC
Many CVEs addressed in this round, please bump to
525.60.11, 515.86.01, 510.108.03, 470.161.03, and 390.157.
Comment 1 Ionen Wolkens gentoo-dev 2022-12-02 17:59:17 UTC
These are already in tree and stabled, just pending cleanup
Comment 2 Ionen Wolkens gentoo-dev 2022-12-02 18:02:21 UTC
(In reply to Ionen Wolkens from comment #1)
> These are already in tree and stabled, just pending cleanup
And guess might as well do it now, hadn't noticed the CVEs yet so thanks (they tend to not mention them during the release).
Comment 3 Larry the Git Cow gentoo-dev 2022-12-02 18:13:19 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=e353fc3204fbc812e1fda4777b3e8929fd946068

commit e353fc3204fbc812e1fda4777b3e8929fd946068
Author:     Ionen Wolkens <ionen@gentoo.org>
AuthorDate: 2022-12-02 18:04:14 +0000
Commit:     Ionen Wolkens <ionen@gentoo.org>
CommitDate: 2022-12-02 18:12:58 +0000

    x11-drivers/nvidia-drivers: drop vulnerable 390.154, 470.141.03, ...
    
    ... 510.85.02, 515.65.01
    
    Bug: https://bugs.gentoo.org/884045
    Signed-off-by: Ionen Wolkens <ionen@gentoo.org>

 x11-drivers/nvidia-drivers/Manifest                |  23 -
 .../files/nvidia-drivers-515.65.01-kernel6.patch   |  19 -
 .../nvidia-drivers/nvidia-drivers-390.154.ebuild   | 506 ------------------
 .../nvidia-drivers-470.141.03.ebuild               | 531 -------------------
 .../nvidia-drivers/nvidia-drivers-510.85.02.ebuild | 540 -------------------
 .../nvidia-drivers/nvidia-drivers-515.65.01.ebuild | 584 ---------------------
 6 files changed, 2203 deletions(-)
Comment 4 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-12-02 19:31:49 UTC
Thanks!
Comment 5 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-05-31 04:17:02 UTC
GLSA request filed
Comment 6 Larry the Git Cow gentoo-dev 2023-10-03 12:47:13 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/data/glsa.git/commit/?id=e0200868c5e75eb57e7355dc8786db0f79271aa3

commit e0200868c5e75eb57e7355dc8786db0f79271aa3
Author:     GLSAMaker <glsamaker@gentoo.org>
AuthorDate: 2023-10-03 12:45:00 +0000
Commit:     Hans de Graaff <graaff@gentoo.org>
CommitDate: 2023-10-03 12:47:03 +0000

    [ GLSA 202310-02 ] NVIDIA Drivers: Multiple Vulnerabilities
    
    Bug: https://bugs.gentoo.org/764512
    Bug: https://bugs.gentoo.org/784596
    Bug: https://bugs.gentoo.org/803389
    Bug: https://bugs.gentoo.org/832867
    Bug: https://bugs.gentoo.org/845063
    Bug: https://bugs.gentoo.org/866527
    Bug: https://bugs.gentoo.org/881341
    Bug: https://bugs.gentoo.org/884045
    Bug: https://bugs.gentoo.org/903614
    Signed-off-by: GLSAMaker <glsamaker@gentoo.org>
    Signed-off-by: Hans de Graaff <graaff@gentoo.org>

 glsa-202310-02.xml | 131 +++++++++++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 131 insertions(+)