Skip to main content

Nvidia warns owners of its GPUs about a dangerous security vulnerability

Nvidia is warning GPU owners to update their graphics card drivers after the company discovered several high-level security vulnerabilities. ThreatPost reports that Nvidia found bugs in its virtual GPU software and the display driver that’s required for the graphics card to function.

Nvidia has a table showing the drivers for its different product lines across Windows and Linux, but it doesn’t really matter. It seems GeForce, Quadro, and Tesla drivers are vulnerable across Windows and Linux, so it’s best to update your graphics driver regardless.

Recommended Videos

In total, the company revealed 13 security vulnerabilities, five through the GPU display driver and eight through the vGPU software. Most sit in between 7 and 8 on CVSS 3.1 (Common Vulnerability Scoring System), which is an open standard for rating security vulnerabilities on a scale of 1 to 10.

CVE‑2021‑1074 is one of the most pressing issues, with a base CVSS score of 7.5. This vulnerability shows up in the display driver installer, where an attacker with local system access can replace the installation files with malicious ones. On the other end, CVE‑2021‑1078 received a base score of 5.5, which shows a vulnerability in the kernel driver that could lead to a system crash.

Image used with permission by copyright holder

There’s also CVE‑2021‑1085 through the vGPU software (base score of 7.3), which opens the potential to write data to shared memory locations and manipulate it after validation. That could lead to escalation of privileges and denial of service.

If you just have an Nvidia graphics card, you don’t need to worry about the vGPU vulnerabilities. The vGPU software is built for the data center, allowing operators to share graphics card power across several virtual machines. Nvidia recommends updating your graphics card driver through the Nvidia driver download page and the vGPU software through the Nvidia licensing portal (if you have access to it).

geforce rtx 3090
Image used with permission by copyright holder

The vulnerabilities highlight the importance of updating your software and drivers regularly. Earlier this year, Nvidia fixed several vulnerabilities in its display driver, and it continues to push updates whenever vulnerabilities show up. The current batch of problems may lead to malicious code execution (ransomware, etc.), escalation of privileges, data disclosure, data corruption, and/or denial of service, so you should update your GPU driver as soon as possible.

All of the issues come through software, so it doesn’t matter which graphics card you have. Even with a last-gen or older GPU — a likely situation given the ongoing graphics card shortage — you still need to update your driver.

Jacob Roach
Lead Reporter, PC Hardware
Jacob Roach is the lead reporter for PC hardware at Digital Trends. In addition to covering the latest PC components, from…
Nvidia RTX 50-series GPUs: performance, specs, prices, availability
The RTX 5090 sitting next to the RTX 4090.

Nvidia has announced its new line of GPUs, the RTX 50-series -- and the first two are almost here, ready to rival the best graphics cards. We were already able to get our hands on the RTX 5090, which is why we now have a better idea of what these cards are capable of.

While we're still waiting for the RTX 5080, RTX 5070 Ti, and RTX 5070, we know that Nvidia is promising some huge leaps in performance, thanks to the new AI powers of DLSS 4. Here's everything you need to know about Nvidia's RTX 50-series.
RTX 50-series: pricing and release date

Read more
AMD could swipe some of the best features of Nvidia GPUs
AMD logo on the RX 7800 XT graphics card.

Nvidia overwhelmingly dominates the list of the best graphics cards, and that largely comes down to its feature set that's been enabled through DLSS. AMD isn't sitting idly by, however. The company is researching new ways to leverage neural networks to enable real-time path tracing on AMD graphics cards -- something that, up to this point, has only really been possible on Nvidia GPUs.

AMD addressed the research in a blog post on GPUOpen, saying that the goal is "moving towards real-time path tracing on RDNA GPUs." Nvidia already uses AI accelerators on RTX graphics cards to upscale an image via DLSS, but AMD is focused on a slightly different angle of performance gains -- denoising.

Read more
It’s finally time to stop buying Nvidia’s RTX 30-series GPUs
RTX 3080 Ti in front of a window.

If you're looking for a budget GPU, the general advice is usually to buy from the previous generation of graphics cards. After all, as the new cards take over the market, the older ones are still waiting to be sold -- and while they're no longer among the best graphics cards, they're still perfectly acceptable alternatives.

We've now reached the point in the current generation of Nvidia GPUs where that advice no longer applies. If you want to get the best bang for your buck, it's time to stop buying Nvidia's RTX 30-series and look for other options.
The RTX 30-series arrived at the worst possible time

Read more