Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:03246-1

Опубликовано: 17 сент. 2025
Источник: suse-cvrf

Описание

Security update for nvidia-open-driver-G06-signed

This update for nvidia-open-driver-G06-signed fixes the following issues:

Updated CUDA variant to 580.82.07:

  • CVE-2025-23277: Fixed access to memory outside bounds permitted under normal use cases in NVIDIA Display Driver (bsc#1247528).
  • CVE-2025-23278: Fixed improper index validation by issuing a call with crafted parameters in NVIDIA Display Driver (bsc#1247529).
  • CVE-2025-23286: Fixed invalid memory read in NVIDIA GPU Display Driver (bsc#1247530).
  • CVE-2025-23283: Fixed stack buffer overflow triggerable by a malicious guest in Virtual GPU Manager in NVIDIA vGPU software (bsc#1247531).
  • CVE-2025-23279: Fixed race condition that leads to privileges escalations in NVIDIA .run Installer (bsc#1247532).

Update non-CUDA variant to 580.82.07 (bsc#1249235).

Other fixes:

  • Added Requires to be provided by special versions of nvidia-modprobe and nvidia-persitenced built against SP4 (bsc#1237208, jsc#PED-13295).
  • Get rid of rule of older KMPs not to load nvidia_drm module,
    which are still installed in parallel and therefore still
    active (bsc#1247923).

Список пакетов

SUSE Linux Enterprise Module for Basesystem 15 SP7
nv-prefer-signed-open-driver-580.82.07-150700.3.21.1
nvidia-open-driver-G06-signed-cuda-default-devel-580.82.07-150700.3.21.1
nvidia-open-driver-G06-signed-cuda-kmp-64kb-580.82.07_k6.4.0_150700.53.11-150700.3.21.1
nvidia-open-driver-G06-signed-cuda-kmp-default-580.82.07_k6.4.0_150700.53.11-150700.3.21.1
nvidia-open-driver-G06-signed-default-devel-580.82.07-150700.3.21.1
nvidia-open-driver-G06-signed-kmp-64kb-580.82.07_k6.4.0_150700.53.11-150700.3.21.1
nvidia-open-driver-G06-signed-kmp-default-580.82.07_k6.4.0_150700.53.11-150700.3.21.1

Описание

NVIDIA Display Driver for Linux and Windows contains a vulnerability in the kernel mode driver, where an attacker could access memory outside bounds permitted under normal use cases. A successful exploit of this vulnerability might lead to denial of service, data tampering, or information disclosure.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:nv-prefer-signed-open-driver-580.82.07-150700.3.21.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:nvidia-open-driver-G06-signed-cuda-default-devel-580.82.07-150700.3.21.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:nvidia-open-driver-G06-signed-cuda-kmp-64kb-580.82.07_k6.4.0_150700.53.11-150700.3.21.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:nvidia-open-driver-G06-signed-cuda-kmp-default-580.82.07_k6.4.0_150700.53.11-150700.3.21.1

Ссылки

Описание

NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker might cause an improper index validation by issuing a call with crafted parameters. A successful exploit of this vulnerability might lead to data tampering or denial of service.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:nv-prefer-signed-open-driver-580.82.07-150700.3.21.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:nvidia-open-driver-G06-signed-cuda-default-devel-580.82.07-150700.3.21.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:nvidia-open-driver-G06-signed-cuda-kmp-64kb-580.82.07_k6.4.0_150700.53.11-150700.3.21.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:nvidia-open-driver-G06-signed-cuda-kmp-default-580.82.07_k6.4.0_150700.53.11-150700.3.21.1

Ссылки

Описание

NVIDIA .run Installer for Linux and Solaris contains a vulnerability where an attacker could use a race condition to escalate privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, denial of service, or data tampering.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:nv-prefer-signed-open-driver-580.82.07-150700.3.21.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:nvidia-open-driver-G06-signed-cuda-default-devel-580.82.07-150700.3.21.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:nvidia-open-driver-G06-signed-cuda-kmp-64kb-580.82.07_k6.4.0_150700.53.11-150700.3.21.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:nvidia-open-driver-G06-signed-cuda-kmp-default-580.82.07_k6.4.0_150700.53.11-150700.3.21.1

Ссылки

Описание

NVIDIA vGPU software for Linux-style hypervisors contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause stack buffer overflow. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, or data tampering.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:nv-prefer-signed-open-driver-580.82.07-150700.3.21.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:nvidia-open-driver-G06-signed-cuda-default-devel-580.82.07-150700.3.21.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:nvidia-open-driver-G06-signed-cuda-kmp-64kb-580.82.07_k6.4.0_150700.53.11-150700.3.21.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:nvidia-open-driver-G06-signed-cuda-kmp-default-580.82.07_k6.4.0_150700.53.11-150700.3.21.1

Ссылки

Описание

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an attacker could read invalid memory. A successful exploit of this vulnerability might lead to information disclosure.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:nv-prefer-signed-open-driver-580.82.07-150700.3.21.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:nvidia-open-driver-G06-signed-cuda-default-devel-580.82.07-150700.3.21.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:nvidia-open-driver-G06-signed-cuda-kmp-64kb-580.82.07_k6.4.0_150700.53.11-150700.3.21.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:nvidia-open-driver-G06-signed-cuda-kmp-default-580.82.07_k6.4.0_150700.53.11-150700.3.21.1

Ссылки