¡¾Îó²îͨ¸æ¡¿NVIDIA¶à¸öÇå¾²Îó²î

Ðû²¼Ê±¼ä 2021-01-11

0x00 Îó²î¸ÅÊö

NVIDIAÊÇGPU(ͼÐδ¦Öóͷ£Æ÷)µÄ·¢Ã÷Õß,Ò²ÊÇÈ˹¤ÖÇÄÜÅÌËãµÄÒýÁìÕß¡£¡£¡£

2021Äê01ÔÂ07ÈÕ£¬£¬£¬ £¬£¬£¬£¬NVIDIAÐû²¼Á˶à¸öÇå¾²¸üУ¬£¬£¬ £¬£¬£¬£¬±¾´Î¸üÐÂÐÞ¸´ÁËNVIDIA GPUÏÔʾÇý¶¯³ÌÐòÖеÄ6¸öÇå¾²Îó²îºÍvGPUÖÎÀíÈí¼þÖеÄ10¸öÇå¾²Îó²î£¬£¬£¬ £¬£¬£¬£¬ÕâЩÎó²î»áÓ°ÏìWindowsºÍLinuxϵͳ£¬£¬£¬ £¬£¬£¬£¬×îÖÕµ¼Ö¾ܾøÐ§ÀÍ¡¢È¨ÏÞÌáÉý¡¢Êý¾Ý¸Ä¶¯»òÐÅϢй¶¡£¡£¡£

 

0x01 Îó²îÏêÇé

image.png

±¾´Î¹²Ðû²¼µÄ16¸öÇå¾²Îó²îÖУ¬£¬£¬ £¬£¬£¬£¬ÆäÖÐÓÐ11¸öÆÀ¼¶Îª¸ßΣ£¬£¬£¬ £¬£¬£¬£¬ÈçÏ£º

CVE ID

ÐÎò

»ùÌìÖ°Êý

²úÆ·

CVE?2021?1051

ÓÃÓÚWindowsµÄNVIDIA GPUÏÔʾÇý¶¯nvlddmkm.sys³ÌÐòÔÚDxgkDdiEscapeµÄÄÚºËģʽ²ã£¨£©´¦Öóͷ£³ÌÐòÖаüÀ¨Ò»¸öÎó²î£¬£¬£¬ £¬£¬£¬£¬ÔÚ¸ÃÎó²îÖÐÖ´ÐвÙ×÷¿ÉÄܻᵼÖ¾ܾøÐ§ÀÍ»òȨÏÞÌáÉý¡£¡£¡£

8.4

NVIDIA   GPU

CVE?2021?1052

ÊÊÓÃÓÚWindowsºÍLinuxµÄNVIDIA GPUÏÔʾÇý¶¯nvlddmkm.sys³ÌÐòÔÚDxgkDdiEscape»òIOCTLµÄÄÚºËģʽ²ã£¨£©´¦Öóͷ£³ÌÐòÖаüÀ¨Ò»¸öÎó²î£¬£¬£¬ £¬£¬£¬£¬ÆäÖÐÓû§Ä£Ê½¿Í»§¶Ë¿ÉÒÔ»á¼û¾ÉÓÐȨÏÞµÄAPI£¬£¬£¬ £¬£¬£¬£¬Õâ¿ÉÄܵ¼Ö¾ܾøÐ§ÀÍ¡¢È¨ÏÞÉý¼¶ºÍÐÅϢй¶¡£¡£¡£

7.8

NVIDIA   GPU

CVE?2021?1053

ÊÊÓÃÓÚWindowsºÍLinuxµÄNVIDIA GPUÏÔʾÇý¶¯nvlddmkm.sys³ÌÐòÔÚDxgkDdiEscape»òIOCTLµÄÄÚºËģʽ²ã£¨£©´¦Öóͷ£³ÌÐòÖаüÀ¨Ò»¸öÎó²î£¬£¬£¬ £¬£¬£¬£¬ÆäÖжÔÓû§Ö¸ÕëµÄ²»×¼È·ÑéÖ¤¿ÉÄܻᵼÖ¾ܾøÐ§ÀÍ¡£¡£¡£

6.6

NVIDIA   GPU

CVE?2021?1054

ÊÊÓÃÓÚWindowsµÄNVIDIA GPUÏÔʾÇý¶¯nvlddmkm.sys³ÌÐòÔÚDxgkDdiEscapeµÄÄÚºËģʽ²ã£¨£©´¦Öóͷ£³ÌÐòÖаüÀ¨Ò»¸öÎó²î£¬£¬£¬ £¬£¬£¬£¬µ±¼ÓÈëÕßʵÑé»á¼û×ÊÔ´»òÖ´ÐвÙ×÷ʱ£¬£¬£¬ £¬£¬£¬£¬¸ÃÈí¼þ²»Ö´Ðлò²»×¼È·µØÖ´ÐÐÊÚȨ¼ì²é£¬£¬£¬ £¬£¬£¬£¬Õâ¿ÉÄܵ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£

6.5

NVIDIA   GPU

CVE?2021?1055

ÊÊÓÃÓÚWindowsµÄNVIDIA GPUÏÔʾÇý¶¯nvlddmkm.sys³ÌÐòÔÚDxgkDdiEscapeµÄÄÚºËģʽ²ã£¨£©´¦Öóͷ£³ÌÐòÖаüÀ¨Ò»¸öÎó²î£¬£¬£¬ £¬£¬£¬£¬ÆäÖлá¼û¿ØÖƲ»µ±¿ÉÄܵ¼Ö¾ܾøÐ§ÀͺÍÐÅϢй¶¡£¡£¡£

5.3

NVIDIA   GPU

CVE?2021?1056

ÓÃÓÚLinuxµÄNVIDIA GPUÏÔʾÇý¶¯³ÌÐòÔÚÄÚºËģʽ²ã£¨nvidia.ko£©ÖаüÀ¨Ò»¸öÎó²î£¬£¬£¬ £¬£¬£¬£¬ÔÚ¸ÃÎó²îÖУ¬£¬£¬ £¬£¬£¬£¬ËüûÓÐÍêÈ«×ñÊØ²Ù×÷ϵͳÎļþϵͳÌṩGPU×°±¸¼¶¸ôÀëµÄȨÏÞ£¬£¬£¬ £¬£¬£¬£¬Õâ¿ÉÄܵ¼Ö¾ܾøÐ§ÀÍ»òÐÅϢй¶¡£¡£¡£

5.3

NVIDIA   GPU

CVE?2021?1057

NVIDIA vGPUÖÎÀíÆ÷ÔÚvGPU²å¼þÖаüÀ¨Ò»¸öÎó²î£¬£¬£¬ £¬£¬£¬£¬¸ÃÎó²îʹ·Ã¿Í¿ÉÒÔ·ÖÅÉһЩδ¾­·Ã¿ÍÊÚȨµÄ×ÊÔ´£¬£¬£¬ £¬£¬£¬£¬Õâ¿ÉÄܵ¼ÖÂÍêÕûÐÔºÍÉñÃØÐÔɥʧ¡¢¾Ü¾øÐ§ÀÍ»òÐÅϢй¶¡£¡£¡£

7.8

NVIDIA   VGPU

CVE?2021?1058

NVIDIA vGPUÈí¼þÔÚÀ´±öÄÚºËģʽÇý¶¯³ÌÐòºÍvGPU²å¼þÖаüÀ¨Ò»¸öÎó²î£¬£¬£¬ £¬£¬£¬£¬ÔÚ¸ÃÎó²îÖУ¬£¬£¬ £¬£¬£¬£¬Î´ÑéÖ¤ÊäÈëÊý¾Ý¾Þϸ£¬£¬£¬ £¬£¬£¬£¬Õâ¿ÉÄܻᵼÖÂÊý¾Ý¸Ä¶¯»ò¾Ü¾øÐ§ÀÍ¡£¡£¡£

7.8

NVIDIA   VGPU

CVE?2021?1059

NVIDIA vGPUÖÎÀíÆ÷ÔÚvGPU²å¼þÖаüÀ¨Ò»¸öÎó²î£¬£¬£¬ £¬£¬£¬£¬¸ÃÎó²îÖеÄÊäÈëË÷ÒýδÂÄÀúÖ¤£¬£¬£¬ £¬£¬£¬£¬Õâ¿ÉÄܵ¼ÖÂÕûÊýÒç³ö£¬£¬£¬ £¬£¬£¬£¬½ø¶ø¿ÉÄܵ¼ÖÂÊý¾Ý¸Ä¶¯¡¢ÐÅϢй¶»ò¾Ü¾øÐ§ÀÍ¡£¡£¡£

7.8

NVIDIA   VGPU

CVE?2021?1060

NVIDIA vGPUÈí¼þÔÚÀ´±öÄÚºËģʽÇý¶¯³ÌÐòºÍvGPU²å¼þÖаüÀ¨Ò»¸öÎó²î£¬£¬£¬ £¬£¬£¬£¬¸ÃÎó²îÖеÄÊäÈëË÷ÒýδÂÄÀúÖ¤£¬£¬£¬ £¬£¬£¬£¬Õâ¿ÉÄܵ¼ÖÂÊý¾Ý¸Ä¶¯»ò¾Ü¾øÐ§ÀÍ¡£¡£¡£

7.8

NVIDIA   VGPU

CVE?2021?1061

NVIDIA vGPUÖÎÀíÆ÷ÔÚvGPU²å¼þÖаüÀ¨Ò»¸öÎó²î£¬£¬£¬ £¬£¬£¬£¬ÔÚÕâÖÖÇéÐÎÏ£¬£¬£¬ £¬£¬£¬£¬¾ºÕù״̬¿ÉÄܵ¼ÖÂvGPU²å¼þ¼ÌÐøÊ¹ÓÃ֮ǰ¾­ÓÉÑéÖ¤µÄ£¬£¬£¬ £¬£¬£¬£¬ÒѸü¸ÄµÄ×ÊÔ´£¬£¬£¬ £¬£¬£¬£¬´Ó¶ø¿ÉÄܵ¼Ö¾ܾøÐ§ÀÍ»òÐÅϢй¶¡£¡£¡£

7.8

NVIDIA   VGPU

CVE?2021?1062

NVIDIA vGPUÖÎÀíÆ÷ÔÚvGPU²å¼þÖаüÀ¨Ò»¸öÎó²î£¬£¬£¬ £¬£¬£¬£¬¸ÃÎó²îÖеÄÊäÈëÊý¾Ý³¤¶ÈδÂÄÀúÖ¤£¬£¬£¬ £¬£¬£¬£¬Õâ¿ÉÄܵ¼ÖÂÊý¾Ý¸Ä¶¯»ò¾Ü¾øÐ§ÀÍ¡£¡£¡£

7.8

NVIDIA   VGPU

CVE?2021?1063

NVIDIA vGPUÖÎÀíÆ÷ÔÚvGPU²å¼þÖаüÀ¨Ò»¸öÎó²î£¬£¬£¬ £¬£¬£¬£¬¸ÃÎó²îÖеÄÊäÈëÆ«ÒÆÎ´¾­ÓÉÑéÖ¤£¬£¬£¬ £¬£¬£¬£¬Õâ¿ÉÄܵ¼Ö»º³åÇøÒç³ö£¬£¬£¬ £¬£¬£¬£¬½ø¶øµ¼ÖÂÊý¾Ý¸Ä¶¯¡¢ÐÅϢй¶»ò¾Ü¾øÐ§ÀÍ¡£¡£¡£

7.8

NVIDIA   VGPU

CVE?2021?1064

NVIDIA vGPUÖÎÀíÆ÷ÔÚvGPU²å¼þÖаüÀ¨Ò»¸öÎó²î£¬£¬£¬ £¬£¬£¬£¬ÆäÖиÃÎó²î´Ó²»ÊÜÐÅÈεÄȪԴ»ñȡֵ£¬£¬£¬ £¬£¬£¬£¬½«¸Ãֵת»»ÎªÖ¸Õ룬£¬£¬ £¬£¬£¬£¬È»ºó×÷·Ï¶ÔЧ¹ûÖ¸ÕëµÄÒýÓ㬣¬£¬ £¬£¬£¬£¬Õâ¿ÉÄܵ¼ÖÂÐÅϢй¶»ò¾Ü¾øÐ§ÀÍ¡£¡£¡£

7.8

NVIDIA   VGPU

CVE?2021?1065

NVIDIA vGPU ManagerÔÚvGPU²å¼þÖаüÀ¨Ò»¸öÎó²î£¬£¬£¬ £¬£¬£¬£¬¸ÃÎó²îÖеÄÊäÈëÊý¾ÝδÂÄÀúÖ¤£¬£¬£¬ £¬£¬£¬£¬Õâ¿ÉÄܻᵼÖÂÊý¾Ý¸Ä¶¯»ò¾Ü¾øÐ§ÀÍ¡£¡£¡£

7.8

NVIDIA   VGPU

CVE?2021?1066

NVIDIA vGPU ManagerÔÚvGPU²å¼þÖаüÀ¨Ò»¸öÎó²î£¬£¬£¬ £¬£¬£¬£¬¸ÃÎó²îÖеÄÊäÈëÊý¾ÝδÂÄÀúÖ¤£¬£¬£¬ £¬£¬£¬£¬Õâ¿ÉÄܵ¼ÖÂ×ÊÔ´ÒâÍâÏûºÄ£¬£¬£¬ £¬£¬£¬£¬½ø¶øµ¼Ö¾ܾøÐ§ÀÍ¡£¡£¡£

5.5

NVIDIA   VGPU

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ£¬£¬£¬ £¬£¬£¬£¬NVIDIAÒѾ­ÐÞ¸´Á˲¿·ÖÎó²î£¬£¬£¬ £¬£¬£¬£¬½¨Òé²Î¿¼Ï±íʵʱ¸üС£¡£¡£

NVIDIA GPU£º

ÒÑÐÞ¸´µÄCVE ID

Èí¼þ²úÆ·

²Ù×÷ϵͳ

Driver Branch

ÊÜÓ°ÏìµÄ°æ±¾

ÐÞ¸´°æ±¾

CVE?2021?1051
  CVE?2021?1052
  CVE?2021?1053
  CVE?2021?1054
  CVE?2021?1055

GeForce

Windows

R460

461.09֮ǰµÄËùÓа汾

461.09

NVIDIA RTX / Quadro¡¢NVS

Windows

R460

461.09֮ǰµÄËùÓа汾

461.09

R450

452.77֮ǰµÄËùÓа汾

452.77

R390

392.63֮ǰµÄËùÓа汾

392.63

Tesla

Windows

R460

461.09֮ǰµÄËùÓа汾

461.09

R450

452.77֮ǰµÄËùÓа汾

452.77

R418

427.11֮ǰµÄËùÓа汾

427.11

 

ÒÑÐÞ¸´µÄCVE ID

Èí¼þ²úÆ·

²Ù×÷ϵͳ

Driver Branch

ÊÜÓ°ÏìµÄ°æ±¾

ÐÞ¸´°æ±¾

CVE?2021?1052
  CVE?2021?1053
  CVE?2021?1056

GeForce

Linux

R460

460.32.03֮ǰµÄËùÓа汾

460.32.03

R450

450.102.04֮ǰµÄËùÓа汾

450.102.04

NVIDIA RTX / Quadro¡¢NVS

Linux

R460

460.32.03֮ǰµÄËùÓа汾

460.32.03

R450

450.102.04֮ǰµÄËùÓа汾

450.102.04

R390

390.141֮ǰµÄËùÓа汾

390.141

Tesla

Linux

R460

ËùÓа汾

2021Äê1ÔÂ18ÈÕÐû²¼

R450

ËùÓа汾

2021Äê1ÔÂ18ÈÕÐû²¼

R418

ËùÓа汾

2021Äê1ÔÂ18ÈÕÐû²¼

 

NVIDIA vGPU£º

           

ÒÑÐÞ¸´CVE ID

vGPU×é¼þ

²Ù×÷ϵͳ

ÊÜÓ°Ïì°æ±¾

ÐÞ¸´°æ±¾


vGPUÈí¼þ

Driver

vGPUÈí¼þ

Driver


CVE?2021?1058
  CVE?2021?1060

vGPUÈí¼þ£¨·Ã¿ÍÇý¶¯³ÌÐò£©

Windows

11.3֮ǰµÄËùÓа汾

452.77֮ǰµÄËùÓа汾

11.3

452.77




8.6֮ǰµÄËùÓа汾

427.11֮ǰµÄËùÓа汾

8.6

427.11


vGPUÈí¼þ£¨·Ã¿ÍÇý¶¯³ÌÐò£©

Linux

11.3֮ǰµÄËùÓа汾

450.102.04֮ǰµÄËùÓа汾

11.3

450.102.04



8.6֮ǰµÄËùÓа汾

418.181.07֮ǰµÄËùÓа汾

8.6

418.181.07



CVE?2021?1057
  CVE?2021?1058
  CVE?2021?1059
  CVE?2021?1060
  CVE?2021?1061
  CVE?2021?1062
  CVE?2021?1063
  CVE?2021?1064
  CVE?2021?1065
  CVE?2021?1066

vGPUÈí¼þ£¨ÐéÄâGPUÖÎÀíÆ÷£©

Citrix Hypervisor£¬£¬£¬ £¬£¬£¬£¬VMware   vSphere£¬£¬£¬ £¬£¬£¬£¬ºìñÆóÒµLinux KVM¡¢Nutanix   AHV

11.3֮ǰµÄËùÓа汾

450.102֮ǰµÄËùÓа汾

11.3

450.102



8.6֮ǰµÄËùÓа汾

418.181֮ǰµÄËùÓа汾

8.6

418.181




0x03 ²Î¿¼Á´½Ó

https://nvidia.custhelp.com/app/answers/detail/a_id/5142/kw/Security%20Bulletin

https://www.bleepingcomputer.com/news/security/nvidia-fixes-high-severity-flaws-affecting-windows-linux-devices/

 

0x04 ʱ¼äÏß

2021-01-07  NVIDIAÐû²¼Çå¾²¸üÐÂ

2021-01-11  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png