CVE-2022-34673
Bottlerocket vulnerability analysis and mitigation

Overview

CVE-2022-34673 is a security vulnerability discovered in the NVIDIA GPU Display Driver for Linux, specifically affecting the kernel mode layer (nvidia.ko). The vulnerability involves an out-of-bounds array access that could potentially lead to denial of service, information disclosure, or data tampering. The vulnerability was disclosed in November 2022 and has a CVSS v3.1 base score of 4.4, indicating a relatively low severity level (NVIDIA Security).

Technical details

The vulnerability exists in the kernel mode layer (nvidia.ko) of the NVIDIA GPU Display Driver for Linux. It is characterized by an out-of-bounds array access vulnerability with a CVSS vector of AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L. The vulnerability requires local access and low privileges to exploit, with potential impacts on system integrity and availability being rated as low (NVIDIA Security).

Impact

The exploitation of this vulnerability can lead to three primary consequences: denial of service affecting system availability, unauthorized information disclosure compromising data confidentiality, and data tampering affecting system integrity. The overall impact is considered relatively low based on the CVSS score of 4.4 (NVIDIA Security).

Mitigation and workarounds

NVIDIA has released security updates to address this vulnerability. For Linux systems, the fixed versions vary by driver branch: R515 users should upgrade to version 515.86.01 or later, R510 users to 510.108.03 or later, R470 users to 470.161.03 or later, and R390 users to 390.157 or later. Users are strongly recommended to update their NVIDIA GPU drivers to the latest version available for their respective branch (NVIDIA Security).

Additional resources


SourceThis report was generated using AI

Related Bottlerocket vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-45492CRITICAL9.8
  • BottlerocketBottlerocket
  • expat-debugsource
NoYesAug 30, 2024
CVE-2024-45491CRITICAL9.8
  • BottlerocketBottlerocket
  • expat-debugsource
NoYesAug 30, 2024
CVE-2022-21505MEDIUM6.7
  • NixOSNixOS
  • kernel-debug-modules-extra
NoYesDec 24, 2024
CVE-2022-28693MEDIUM4.7
  • Linux KernelLinux Kernel
  • kernel-azure-optional
NoYesFeb 14, 2025
CVE-2024-45310LOW3.6
  • cAdvisorcAdvisor
  • neuvector-scanner-fips
NoYesSep 03, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management