Improper Access Control The advisory has been revoked - it doesn't affect any version of package nvidia-graphics-drivers-304  (opens in a new tab)


Threat Intelligence

EPSS
0.25% (65th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Improper Access Control vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-UBUNTU1504-NVIDIAGRAPHICSDRIVERS304-625950
  • published24 Nov 2015
  • disclosed24 Nov 2015

Introduced: 24 Nov 2015

CVE-2015-5053  (opens in a new tab)
CWE-284  (opens in a new tab)

Amendment

The Ubuntu security team deemed this advisory irrelevant for Ubuntu:15.04.

NVD Description

Note: Versions mentioned in the description apply only to the upstream nvidia-graphics-drivers-304 package and not the nvidia-graphics-drivers-304 package as distributed by Ubuntu.

The host memory mapping path feature in the NVIDIA GPU graphics driver R346 before 346.87 and R352 before 352.41 for Linux and R352 before 352.46 for GRID vGPU and vSGA does not properly restrict access to third-party device IO memory, which allows attackers to gain privileges, cause a denial of service (resource consumption), or possibly have unspecified other impact via unknown vectors related to the follow_pfn kernel-mode API call.