CVE-2024-0149 Details
Description
NVIDIA GPU Display Driver for Linux contains a vulnerability which could allow an attacker unauthorized access to files. A successful exploit of this vulnerability might lead to limited information disclosure.
A vulnerability in the NVIDIA GPU Display Driver for Linux could allow an attacker to gain unauthorized access to files. Exploitation of this vulnerability may result in limited information disclosure. The issue is present in the driver versions prior to 550.144.03.
Users can update to NVIDIA GPU Display Driver version 550.144.03 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 28, 2025CISA-ADP
Assessed Jan 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2025/03/27/7 | CVE | ExploitMailing ListRemedyTechnical Analysis |
| https://nvidia.custhelp.com/app/answers/detail/a_id/5614 | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| NVIDIA GPU Display Driver | < 570.86.16 (semver) < 572.16 < 550.144.03 (semver) < 553.62 < 535.230.02 (semver) < 539.19 |
CPE
Remediation
| |
| NVIDIA vGPU Software | All versions |
CPE
Remediation
| |
| NVIDIA nvidia-modprobe | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 27, 2025 | CVE Modified | CVE |
| Jan 28, 2025 | New CVE Received | [email protected] |
Volerion