Name | CVE-2016-7389 |
Description | For the NVIDIA Quadro, NVS, GeForce, and Tesla products, NVIDIA GPU Display Driver on Linux R304 before 304.132, R340 before 340.98, R367 before 367.55, R361_93 before 361.93.03, and R370 before 370.28 contains a vulnerability in the kernel mode layer (nvidia.ko) handler for mmap() where improper input validation may allow users to gain access to arbitrary physical memory, leading to an escalation of privileges. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Debian Bugs | 846331, 846332, 846333 |
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|---|---|---|
nvidia-graphics-drivers (PTS) | bullseye/non-free | 470.256.02-2 | fixed |
bookworm/non-free-firmware | 535.183.01-1~deb12u1 | fixed | |
sid/non-free-firmware, trixie/non-free-firmware | 535.183.06-1 | fixed | |
nvidia-graphics-drivers-legacy-340xx (PTS) | sid/non-free | 340.108-22 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|---|---|---|---|---|---|
nvidia-graphics-drivers | source | jessie | 340.101-1 | |||
nvidia-graphics-drivers | source | (unstable) | 367.57-1 | 846331 | ||
nvidia-graphics-drivers-legacy-304xx | source | jessie | 304.134-0~deb8u1 | |||
nvidia-graphics-drivers-legacy-304xx | source | (unstable) | 304.132-1 | 846333 | ||
nvidia-graphics-drivers-legacy-340xx | source | (unstable) | 340.98-1 | 846332 |
[wheezy] - nvidia-graphics-drivers <no-dsa> (Non-free not supported)
http://nvidia.custhelp.com/app/answers/detail/a_id/4246