CVE-2014-8298

UnknownEPSS 3.04%

Last modified

CVE-2014-8298 is a vulnerability of currently unknown severity. The NVIDIA Linux Discrete GPU drivers before R304.125, R331.x before R331.113, R340.x before R340.65, R343.x before R343.36, and R346.x before R346.22, Linux for Tegra (L4T) driver before R21.2, and Chrome OS driver before R40 allows remote attackers to cause a denial of service (segmentation fault and X server crash) or possibly execute arbitrary code via a crafted GLX indirect rendering protocol request.. EPSS estimates a 3.04% chance of exploitation in the next 30 days.

Description

The NVIDIA Linux Discrete GPU drivers before R304.125, R331.x before R331.113, R340.x before R340.65, R343.x before R343.36, and R346.x before R346.22, Linux for Tegra (L4T) driver before R21.2, and Chrome OS driver before R40 allows remote attackers to cause a denial of service (segmentation fault and X server crash) or possibly execute arbitrary code via a crafted GLX indirect rendering protocol request.

Metrics

EPSS Probability
3.04%

85.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
NvidiaGpu Driverr304.125
NvidiaGpu Driverr331.00
NvidiaGpu Driverr331.112
NvidiaGpu Driverr340.00
NvidiaGpu Driverr340.65
NvidiaGpu Driverr343.00
NvidiaGpu Driverr343.36
NvidiaGpu Driverr346.00
NvidiaGpu Driverr346.22
NvidiaGpu Driver<= r21.2
NvidiaGpu Driver<= r39

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2014-8298?
The NVIDIA Linux Discrete GPU drivers before R304.125, R331.x before R331.113, R340.x before R340.65, R343.x before R343.36, and R346.x before R346.22, Linux for Tegra (L4T) driver before R21.2, and Chrome OS driver before R40 allows remote attackers to cause a denial of service (segmentation fault and X server crash) or possibly execute arbitrary code via a crafted GLX indirect rendering protocol request.
How severe is CVE-2014-8298?
Severity scoring for CVE-2014-8298 is pending analysis. The EPSS model estimates a 3.04% probability of exploitation in the next 30 days.
How do I fix CVE-2014-8298?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2014-8298?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST