SUSE-SU-2024:0772-1
Dashboard / Vulnerabilities / SUSE-SU-2024:0772-1
SUSE-SU-2024:0772-1
Summary: Security update for kernel-firmware-nvidia-gspx-G06, nvidia-open-driver-G06-signed
Details: This update for kernel-firmware-nvidia-gspx-G06, nvidia-open-driver-G06-signed fixes the following issues: Update to 550.54.14: * Added vGPU Host and vGPU Guest support. For vGPU Host, please refer to the README.vgpu packaged in the vGPU Host Package for more details. Security issues fixed: * CVE-2024-0074: A user could trigger a NULL ptr dereference. * CVE-2024-0075: A user could overwrite the end of a buffer, leading to crashes or code execution. * CVE-2022-42265: A unprivileged user could trigger an integer overflow which could lead to crashes or code execution. - create /run/udev/static_node-tags/uaccess/nvidia${devid} symlinks also during modprobing the nvidia module; this changes the issue of not having access to /dev/nvidia${devid}, when gfxcard has been replaced by a different gfx card after installing the driver - provide nvidia-open-driver-G06-kmp (jsc#PED-7117) This makes it easy to replace the package from nVidia's CUDA repository with this presigned package
References: https://www.suse.com/support/update/announcement/2024/suse-su-20240772-1/, https://bugzilla.suse.com/1220552, https://www.suse.com/security/cve/CVE-2022-42265, https://www.suse.com/security/cve/CVE-2024-0074, https://www.suse.com/security/cve/CVE-2024-0075
Affected packages
Package
Name: kernel-firmware-nvidia-gspx-G06
Purl: pkg:rpm/suse/kernel-firmware-nvidia-gspx-G06&distro=SUSE%20Linux%20Enterprise%20Micro%205.5
Affected ranges
Type: ECOSYSTEM
Events:
