¡¾·ì϶¹«¸æ¡¿NVIDIA¶à¸ö°²È«·ì϶

°ä²¼¹¦·ò 2021-01-11

0x00 ·ì϶¸ÅÊö

NVIDIAÊÇGPU(ͼÐδ¦ÖÃÆ÷)µÄ·¢ÏÖÕß,Ò²ÊÇÈËΪÖÇÄÜÍÆËãµÄÒýÁìÕß¡£

2021Äê01ÔÂ07ÈÕ£¬NVIDIA°ä²¼Á˶à¸ö°²È«¸üУ¬±¾´Î¸üн¨¸´ÁËNVIDIA GPUÏÔʾÇý¶¯·¨Ê½ÖеÄ6¸ö°²È«·ì϶ºÍvGPUÖÎÀíÈí¼þÖеÄ10¸ö°²È«·ì϶£¬ÕâЩ·ì϶»áÓ°ÏìWindowsºÍLinuxϵͳ£¬×îÖÕµ¼Ö»ؾø·þÎñ¡¢È¨ÏÞÌáÉý¡¢Êý¾Ý´Û¸Ä»òÐÅϢй¶¡£

 

0x01 ·ì϶ÏêÇé

image.png

±¾´Î¹²°ä²¼µÄ16¸ö°²È«·ì϶ÖУ¬ÆäÖÐÓÐ11¸öÆÀ¼¶Îª¸ßΣ£¬ÈçÏ£º

CVE ID

ÃèÊö

¸ù±¾·ÖÊý

²úÆ·

CVE?2021?1051

ÓÃÓÚWindowsµÄNVIDIA GPUÏÔʾÇý¶¯nvlddmkm.sys·¨Ê½ÔÚDxgkDdiEscapeµÄÄÚºËģʽ²ã£¨£©´¦Ö÷¨Ê½ÖÐÔ̺¬Ò»¸ö·ì϶£¬Ôڸ÷ì϶ÖÐÖ´ÐвÙ×÷¿ÉÄܻᵼÖ»ؾø·þÎñ»òȨÏÞÌáÉý¡£

8.4

NVIDIA   GPU

CVE?2021?1052

ºÏÓÃÓÚWindowsºÍLinuxµÄNVIDIA GPUÏÔʾÇý¶¯nvlddmkm.sys·¨Ê½ÔÚDxgkDdiEscape»òIOCTLµÄÄÚºËģʽ²ã£¨£©´¦Ö÷¨Ê½ÖÐÔ̺¬Ò»¸ö·ì϶£¬ÆäÖÐÓû§Ä£Ê½¿Í»§¶ËÄܹ»½Ó¼û¾ÉÓÐȨÏÞµÄAPI£¬Õâ¿ÉÄܵ¼Ö»ؾø·þÎñ¡¢È¨ÏÞÉý¼¶ºÍÐÅϢй¶¡£

7.8

NVIDIA   GPU

CVE?2021?1053

ºÏÓÃÓÚWindowsºÍLinuxµÄNVIDIA GPUÏÔʾÇý¶¯nvlddmkm.sys·¨Ê½ÔÚDxgkDdiEscape»òIOCTLµÄÄÚºËģʽ²ã£¨£©´¦Ö÷¨Ê½ÖÐÔ̺¬Ò»¸ö·ì϶£¬ÆäÖжÔÓû§Ö¸ÕëµÄ²»ÕýÈ·ÑéÖ¤¿ÉÄܻᵼÖ»ؾø·þÎñ¡£

6.6

NVIDIA   GPU

CVE?2021?1054

ºÏÓÃÓÚWindowsµÄNVIDIA GPUÏÔʾÇý¶¯nvlddmkm.sys·¨Ê½ÔÚDxgkDdiEscapeµÄÄÚºËģʽ²ã£¨£©´¦Ö÷¨Ê½ÖÐÔ̺¬Ò»¸ö·ì϶£¬µ±²Î¼ÓÕß³¢ÊÔ½Ó¼û×ÊÔ´»òÖ´ÐвÙ×÷ʱ£¬¸ÃÈí¼þ²»Ö´Ðлò²»ÕýÈ·µØÖ´ÐÐÊÚȨ²é³­£¬Õâ¿ÉÄܵ¼Ö»ؾø·þÎñ¡£

6.5

NVIDIA   GPU

CVE?2021?1055

ºÏÓÃÓÚWindowsµÄNVIDIA GPUÏÔʾÇý¶¯nvlddmkm.sys·¨Ê½ÔÚDxgkDdiEscapeµÄÄÚºËģʽ²ã£¨£©´¦Ö÷¨Ê½ÖÐÔ̺¬Ò»¸ö·ì϶£¬ÆäÖнӼû½ÚÔì²»µ±¿ÉÄܵ¼Ö»ؾø·þÎñºÍÐÅϢй¶¡£

5.3

NVIDIA   GPU

CVE?2021?1056

ÓÃÓÚLinuxµÄNVIDIA GPUÏÔʾÇý¶¯·¨Ê½ÔÚÄÚºËģʽ²ã£¨nvidia.ko£©ÖÐÔ̺¬Ò»¸ö·ì϶£¬Ôڸ÷ì϶ÖУ¬ËüûÓÐÆëÈ«×ñÊØ²Ù×÷ϵͳÎļþϵͳÌṩGPUÉ豸¼¶¸ôÀëµÄȨÏÞ£¬Õâ¿ÉÄܵ¼Ö»ؾø·þÎñ»òÐÅϢй¶¡£

5.3

NVIDIA   GPU

CVE?2021?1057

NVIDIA vGPUÖÎÀíÆ÷ÔÚvGPU²å¼þÖÐÔ̺¬Ò»¸ö·ì϶£¬¸Ã·ì϶ʹ·Ã¿ÍÄܹ»·ÖÅäһЩδ¾­·Ã¿ÍÊÚȨµÄ×ÊÔ´£¬Õâ¿ÉÄܵ¼ÖÂÆëÈ«ÐԺͻúÃÜÐÔÃÔʧ¡¢»Ø¾ø·þÎñ»òÐÅϢй¶¡£

7.8

NVIDIA   VGPU

CVE?2021?1058

NVIDIA vGPUÈí¼þÔÚÀ´±öÄÚºËģʽÇý¶¯·¨Ê½ºÍvGPU²å¼þÖÐÔ̺¬Ò»¸ö·ì϶£¬Ôڸ÷ì϶ÖУ¬Î´ÑéÖ¤ÊäÈëÊý¾Ý´óÓ×£¬Õâ¿ÉÄܻᵼÖÂÊý¾Ý´Û¸Ä»ò»Ø¾ø·þÎñ¡£

7.8

NVIDIA   VGPU

CVE?2021?1059

NVIDIA vGPUÖÎÀíÆ÷ÔÚvGPU²å¼þÖÐÔ̺¬Ò»¸ö·ì϶£¬¸Ã·ì϶ÖеÄÊäÈëË÷Òýδ¾­ÑéÖ¤£¬Õâ¿ÉÄܵ¼ÖÂÕûÊýÒç³ö£¬½ø¶ø¿ÉÄܵ¼ÖÂÊý¾Ý´Û¸Ä¡¢ÐÅϢй¶»ò»Ø¾ø·þÎñ¡£

7.8

NVIDIA   VGPU

CVE?2021?1060

NVIDIA vGPUÈí¼þÔÚÀ´±öÄÚºËģʽÇý¶¯·¨Ê½ºÍvGPU²å¼þÖÐÔ̺¬Ò»¸ö·ì϶£¬¸Ã·ì϶ÖеÄÊäÈëË÷Òýδ¾­ÑéÖ¤£¬Õâ¿ÉÄܵ¼ÖÂÊý¾Ý´Û¸Ä»ò»Ø¾ø·þÎñ¡£

7.8

NVIDIA   VGPU

CVE?2021?1061

NVIDIA vGPUÖÎÀíÆ÷ÔÚvGPU²å¼þÖÐÔ̺¬Ò»¸ö·ì϶£¬ÔÚÕâÖÖÇé¿öÏ£¬¾ºÕùÇé¿ö¿ÉÄܵ¼ÖÂvGPU²å¼þ³ÖÐøÊ¹ÓÃ֮ǰ¾­¹ýÑéÖ¤µÄ£¬ÒѸü¸ÄµÄ×ÊÔ´£¬´Ó¶ø¿ÉÄܵ¼Ö»ؾø·þÎñ»òÐÅϢй¶¡£

7.8

NVIDIA   VGPU

CVE?2021?1062

NVIDIA vGPUÖÎÀíÆ÷ÔÚvGPU²å¼þÖÐÔ̺¬Ò»¸ö·ì϶£¬¸Ã·ì϶ÖеÄÊäÈëÊý¾Ý³¤¶Èδ¾­ÑéÖ¤£¬Õâ¿ÉÄܵ¼ÖÂÊý¾Ý´Û¸Ä»ò»Ø¾ø·þÎñ¡£

7.8

NVIDIA   VGPU

CVE?2021?1063

NVIDIA vGPUÖÎÀíÆ÷ÔÚvGPU²å¼þÖÐÔ̺¬Ò»¸ö·ì϶£¬¸Ã·ì϶ÖеÄÊäÈëÆ«ÒÆÎ´¾­¹ýÑéÖ¤£¬Õâ¿ÉÄܵ¼Ö»º³åÇøÒç³ö£¬½ø¶øµ¼ÖÂÊý¾Ý´Û¸Ä¡¢ÐÅϢй¶»ò»Ø¾ø·þÎñ¡£

7.8

NVIDIA   VGPU

CVE?2021?1064

NVIDIA vGPUÖÎÀíÆ÷ÔÚvGPU²å¼þÖÐÔ̺¬Ò»¸ö·ì϶£¬ÆäÖи÷ì϶´Ó²»ÊÜÐÅÀµµÄÆðÔ´»ñȡֵ£¬½«¸Ãֵת»»ÎªÖ¸Õ룬¶øºóÈ¡µÞ¶ÔÁ˾ÖÖ¸ÕëµÄÒýÓã¬Õâ¿ÉÄܵ¼ÖÂÐÅϢй¶»ò»Ø¾ø·þÎñ¡£

7.8

NVIDIA   VGPU

CVE?2021?1065

NVIDIA vGPU ManagerÔÚvGPU²å¼þÖÐÔ̺¬Ò»¸ö·ì϶£¬¸Ã·ì϶ÖеÄÊäÈëÊý¾Ýδ¾­ÑéÖ¤£¬Õâ¿ÉÄܻᵼÖÂÊý¾Ý´Û¸Ä»ò»Ø¾ø·þÎñ¡£

7.8

NVIDIA   VGPU

CVE?2021?1066

NVIDIA vGPU ManagerÔÚvGPU²å¼þÖÐÔ̺¬Ò»¸ö·ì϶£¬¸Ã·ì϶ÖеÄÊäÈëÊý¾Ýδ¾­ÑéÖ¤£¬Õâ¿ÉÄܵ¼ÖÂ×ÊÔ´Òâ±í¿÷Ë𣬽ø¶øµ¼Ö»ؾø·þÎñ¡£

5.5

NVIDIA   VGPU

 

0x02 ´ëÖý¨Òé

Ŀǰ£¬NVIDIAÒѾ­½¨¸´Á˲¿ÃÅ·ì϶£¬½¨Òé²Î¿¼Ï±íʵʱ¸üС£

NVIDIA GPU£º

Òѽ¨¸´µÄCVE ID

Èí¼þ²úÆ·

²Ù×÷ϵͳ

Driver Branch

ÊÜÓ°ÏìµÄ°æ±¾

½¨¸´°æ±¾

CVE?2021?1051
  CVE?2021?1052
  CVE?2021?1053
  CVE?2021?1054
  CVE?2021?1055

GeForce

Windows

R460

461.09֮ǰµÄËùÓа汾

461.09

NVIDIA RTX / Quadro¡¢NVS

Windows

R460

461.09֮ǰµÄËùÓа汾

461.09

R450

452.77֮ǰµÄËùÓа汾

452.77

R390

392.63֮ǰµÄËùÓа汾

392.63

Tesla

Windows

R460

461.09֮ǰµÄËùÓа汾

461.09

R450

452.77֮ǰµÄËùÓа汾

452.77

R418

427.11֮ǰµÄËùÓа汾

427.11

 

Òѽ¨¸´µÄCVE ID

Èí¼þ²úÆ·

²Ù×÷ϵͳ

Driver Branch

ÊÜÓ°ÏìµÄ°æ±¾

½¨¸´°æ±¾

CVE?2021?1052
  CVE?2021?1053
  CVE?2021?1056

GeForce

Linux

R460

460.32.03֮ǰµÄËùÓа汾

460.32.03

R450

450.102.04֮ǰµÄËùÓа汾

450.102.04

NVIDIA RTX / Quadro¡¢NVS

Linux

R460

460.32.03֮ǰµÄËùÓа汾

460.32.03

R450

450.102.04֮ǰµÄËùÓа汾

450.102.04

R390

390.141֮ǰµÄËùÓа汾

390.141

Tesla

Linux

R460

ËùÓа汾

2021Äê1ÔÂ18ÈÕ°ä²¼

R450

ËùÓа汾

2021Äê1ÔÂ18ÈÕ°ä²¼

R418

ËùÓа汾

2021Äê1ÔÂ18ÈÕ°ä²¼

 

NVIDIA vGPU£º

           

Òѽ¨¸´CVE ID

vGPU×é¼þ

²Ù×÷ϵͳ

ÊÜÓ°Ïì°æ±¾

½¨¸´°æ±¾


vGPUÈí¼þ

Driver

vGPUÈí¼þ

Driver


CVE?2021?1058
  CVE?2021?1060

vGPUÈí¼þ£¨·Ã¿ÍÇý¶¯·¨Ê½£©

Windows

11.3֮ǰµÄËùÓа汾

452.77֮ǰµÄËùÓа汾

11.3

452.77




8.6֮ǰµÄËùÓа汾

427.11֮ǰµÄËùÓа汾

8.6

427.11


vGPUÈí¼þ£¨·Ã¿ÍÇý¶¯·¨Ê½£©

Linux

11.3֮ǰµÄËùÓа汾

450.102.04֮ǰµÄËùÓа汾

11.3

450.102.04



8.6֮ǰµÄËùÓа汾

418.181.07֮ǰµÄËùÓа汾

8.6

418.181.07



CVE?2021?1057
  CVE?2021?1058
  CVE?2021?1059
  CVE?2021?1060
  CVE?2021?1061
  CVE?2021?1062
  CVE?2021?1063
  CVE?2021?1064
  CVE?2021?1065
  CVE?2021?1066

vGPUÈí¼þ£¨Ðé¹¹GPUÖÎÀíÆ÷£©

Citrix Hypervisor£¬VMware   vSphere£¬ºìñÆóÒµLinux KVM¡¢Nutanix   AHV

11.3֮ǰµÄËùÓа汾

450.102֮ǰµÄËùÓа汾

11.3

450.102



8.6֮ǰµÄËùÓа汾

418.181֮ǰµÄËùÓа汾

8.6

418.181




0x03 ²Î¿¼Á´½Ó

https://nvidia.custhelp.com/app/answers/detail/a_id/5142/kw/Security%20Bulletin

https://www.bleepingcomputer.com/news/security/nvidia-fixes-high-severity-flaws-affecting-windows-linux-devices/

 

0x04 ¹¦·òÏß

2021-01-07  NVIDIA°ä²¼°²È«¸üÐÂ

2021-01-11  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png