Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2012-0952
Linux Debian vulnerability analysis and mitigation

Overview

A heap buffer overflow vulnerability was discovered in the device control ioctl in the Linux driver for Nvidia graphics cards (CVE-2012-0952). The vulnerability allowed an attacker to overflow 49 bytes in the kernel buffer. This security issue was addressed and fixed in Nvidia graphics driver version 295.53 (NVD, Launchpad Bug).

Technical details

The vulnerability stemmed from insufficient size checking in the NV_ESC_CARD_INFO ioctl handler. When processing this ioctl, the driver would write 50 bytes per device to an allocated kernel buffer that was sized according to the input buffer. By providing a minimum 1-byte buffer, an attacker could trigger a 49-byte overflow, as the rm_api->magic check did not abort the ioctl operation (Launchpad Bug).

Impact

The vulnerability could potentially allow an attacker to overflow the kernel heap buffer by 49 bytes, which could lead to privilege escalation or system compromise (NVD).

Exploitability

The vulnerability required local access to the system to exploit the device control ioctl in the Nvidia graphics driver (Launchpad Bug).

Mitigation and workarounds

The vulnerability was fixed in Nvidia graphics driver version 295.53. Users were advised to upgrade to this version or later to address the security issue. Additionally, all supported Ubuntu releases were later upgraded to the 304.x drivers, which also contained the fix (Launchpad Bug).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-94106HIGH8.7
  • Linux Debian logoLinux Debian
  • php-getid3
NoNoSep 20, 2026
CVE-2026-93990HIGH8.7
  • Linux Debian logoLinux Debian
  • expat
NoNoSep 19, 2026
CVE-2026-94108HIGH8.3
  • Linux Debian logoLinux Debian
  • php-getid3
NoNoSep 20, 2026
CVE-2026-93962MEDIUM5.5
  • Linux Debian logoLinux Debian
  • kamailio
NoNoSep 20, 2026
CVE-2026-82560NONEN/A
  • Linux Debian logoLinux Debian
  • perl
NoYesSep 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management