Database/Control plane, storage & DevOps
Nouveau display driver (in-tree Linux nouveau, NV117): Remote denial of service against a workstation or node running
Impact
Remote denial of service against a workstation or node running the open-source Nouveau driver: a crafted pixel shader delivered through a web page wedges the GPU driver and takes the machine's graphics stack down. No code execution, but on a shared render or VDI host it is a free reboot for anyone who can get a browser to load their page.
Who can reach it
Anyone who can get a user on the host to open a web page - so effectively internet-reachable. No local account needed.
What to do
This is the in-tree open-source Nouveau driver, not NVIDIA's proprietary stack. Update the distribution kernel (Ubuntu 18.04 shipped the vulnerable NV117 code) or, on GPU nodes, blacklist nouveau entirely and run the proprietary NVIDIA driver, which is what a compute fleet should be doing anyway. Kernel update means a node reboot.
References
Related entries
- Intel CPUs supporting TSX, including Cascade Lake Xeon Scalable - INTEL-SA-00270: Same class of in-flight data leakCVE-2019-11135 · Intel CPUs supporting TSX, including Cascade Lake Xeon Scalable - INTEL-SA-00270Medium
- Ceph RGW: HTTP header injection via a newline in the CORS ExposeHeader tagCVE-2021-3524 · Ceph RGWMedium
- Ceph: Key length incorrectly passed to the encryption algorithmCVE-2021-3979 · CephMedium
- Slurm (slurmdbd, AccountingStoreFlags=job_script / job_env): When the site turns on job-script and job-environmentCVE-2021-43337 · Slurm (slurmdbd, AccountingStoreFlags=job_script / job_env)Medium
- IBM Spectrum Scale Data Access Services (DAS): An authenticated DAS user inserts code that manipulates clusterCVE-2022-22411 · IBM Spectrum Scale Data Access Services (DAS)Medium
- FlyteAdmin (external IdP access token / ID token expiration check): FlyteAdmin does not enforce expiry on access and IDCVE-2022-31145 · FlyteAdmin (external IdP access token / ID token expiration check)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.