Описание
Security update for nvidia-open-driver-G06-signed
This update for nvidia-open-driver-G06-signed fixes the following issues:
Updated CUDA variant to 580.65.06:
- CVE-2025-23277: Fixed access memory outside bounds permitted under normal use cases in NVIDIA Display Driver (bsc#1247528)
- CVE-2025-23278: Fixed improper index validation by issuing a call with crafted parameters in NVIDIA Display Driver (bsc#1247529)
- CVE-2025-23286: Fixed invalid memory read in NVIDIA GPU Display Driver (bsc#1247530)
- CVE-2025-23283: Fixed stack buffer overflow triggerable by a malicious guest in Virtual GPU Manager in NVIDIA vGPU software (bsc#1247531)
- CVE-2025-23279: Fixed race condition that lead to privileges escalations in NVIDIA .run Installer (bsc#1247532)
Updated non-CUDA variant to 570.172.08 (bsc#1246327)
Список пакетов
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
SUSE Linux Enterprise Micro 5.5
SUSE Linux Enterprise Server 15 SP5-LTSS
SUSE Linux Enterprise Server for SAP Applications 15 SP5
Ссылки
- Link for SUSE-SU-2025:03062-1
- E-Mail link for SUSE-SU-2025:03062-1
- SUSE Security Ratings
- SUSE Bug 1236191
- SUSE Bug 1236658
- SUSE Bug 1236746
- SUSE Bug 1237308
- SUSE Bug 1237585
- SUSE Bug 1239139
- SUSE Bug 1239653
- SUSE Bug 1241231
- SUSE Bug 1242054
- SUSE Bug 1243192
- SUSE Bug 1244614
- SUSE Bug 1246010
- SUSE Bug 1246327
- SUSE Bug 1247528
- SUSE Bug 1247529
- SUSE Bug 1247530
- SUSE Bug 1247531
Описание
NVIDIA Display Driver for Linux and Windows contains a vulnerability in the kernel mode driver, where an attacker could access memory outside bounds permitted under normal use cases. A successful exploit of this vulnerability might lead to denial of service, data tampering, or information disclosure.
Затронутые продукты
Ссылки
- CVE-2025-23277
- SUSE Bug 1247528
Описание
NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker might cause an improper index validation by issuing a call with crafted parameters. A successful exploit of this vulnerability might lead to data tampering or denial of service.
Затронутые продукты
Ссылки
- CVE-2025-23278
- SUSE Bug 1247529
Описание
NVIDIA .run Installer for Linux and Solaris contains a vulnerability where an attacker could use a race condition to escalate privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, denial of service, or data tampering.
Затронутые продукты
Ссылки
- CVE-2025-23279
- SUSE Bug 1247532
Описание
NVIDIA vGPU software for Linux-style hypervisors contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause stack buffer overflow. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.
Затронутые продукты
Ссылки
- CVE-2025-23283
- SUSE Bug 1247531
Описание
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an attacker could read invalid memory. A successful exploit of this vulnerability might lead to information disclosure.
Затронутые продукты
Ссылки
- CVE-2025-23286
- SUSE Bug 1247530