CVE-2016-7382, 2016-7389
Bug #1627055 reported by
Alberto Milone
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
nvidia-graphics-drivers-304 (Ubuntu) |
Fix Released
|
High
|
Alberto Milone | ||
Precise |
Fix Released
|
Undecided
|
Unassigned | ||
Trusty |
Fix Released
|
Undecided
|
Unassigned | ||
Xenial |
Fix Released
|
Undecided
|
Unassigned | ||
nvidia-graphics-drivers-340 (Ubuntu) |
Fix Released
|
High
|
Alberto Milone | ||
Precise |
Fix Released
|
Undecided
|
Unassigned | ||
Trusty |
Fix Released
|
Undecided
|
Unassigned | ||
Xenial |
Fix Released
|
Undecided
|
Unassigned | ||
nvidia-graphics-drivers-367 (Ubuntu) |
Fix Released
|
High
|
Alberto Milone | ||
Precise |
Invalid
|
Undecided
|
Unassigned | ||
Trusty |
Fix Released
|
Undecided
|
Unassigned | ||
Xenial |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
The NVIDIA drivers are affected by a couple of vulnerabilities (CVE-2016-7382, 2016-7389), which NVIDIA are going to disclose on 10/19.
All the NVIDIA drivers in all the supported Ubuntu releases (12.04, 14.04, 16.04) are affected.
I am going to take care of the packaging and of the migrations to the new driver packages.
CVE References
Changed in nvidia-graphics-drivers-304 (Ubuntu): | |
assignee: | nobody → Alberto Milone (albertomilone) |
Changed in nvidia-graphics-drivers-367 (Ubuntu): | |
assignee: | nobody → Alberto Milone (albertomilone) |
Changed in nvidia-graphics-drivers-304 (Ubuntu): | |
importance: | Undecided → High |
Changed in nvidia-graphics-drivers-367 (Ubuntu): | |
importance: | Undecided → High |
Changed in nvidia-graphics-drivers-304 (Ubuntu): | |
status: | New → Triaged |
Changed in nvidia-graphics-drivers-340 (Ubuntu): | |
status: | New → Triaged |
Changed in nvidia-graphics-drivers-367 (Ubuntu): | |
status: | New → Triaged |
Changed in nvidia-graphics-drivers-304 (Ubuntu Precise): | |
status: | New → Triaged |
information type: | Private Security → Public Security |
Changed in nvidia-graphics-drivers-304 (Ubuntu): | |
status: | Triaged → Fix Released |
Changed in nvidia-graphics-drivers-340 (Ubuntu): | |
status: | Triaged → Fix Released |
Changed in nvidia-graphics-drivers-367 (Ubuntu): | |
status: | Triaged → Fix Released |
Changed in nvidia-graphics-drivers-367 (Ubuntu Precise): | |
status: | New → Invalid |
To post a comment you must log in.
This bug was fixed in the package nvidia- graphics- drivers- 304 - 304.132- 0ubuntu0. 16.04.2
--------------- graphics- drivers- 304 (304.132- 0ubuntu0. 16.04.2) xenial-security; urgency=medium
nvidia-
* SECURITY UPDATE: bug-report. sh for kernel messages. DEBUG_VM_ PGFLAGS. templates/ control. in: dkms/patches/ buildfix_ kernel_ 4.3.patch: templates/ nvidia- graphics- drivers. postinst. in:
- CVE-2016-7382, 2016-7389 (LP: #1627055).
* New upstream release:
- Added /var/log/dmesg to the list of paths which are searched by
nvidia-
- Fixed a bug that caused kernel panics when using the NVIDIA
driver on v4.5 and newer Linux kernels built with
CONFIG_
* debian/
- Add transitional packages to deprecate the -updates flavour.
* debian/
- Refresh the patch.
* debian/
- Do not fail if update-initramfs is not available (LP: #1629274).
-- Alberto Milone <email address hidden> Thu, 13 Oct 2016 17:23:23 +0200