Skip to main content

Nvidia warns owners of its GPUs about a dangerous security vulnerability

Nvidia is warning GPU owners to update their graphics card drivers after the company discovered several high-level security vulnerabilities. ThreatPost reports that Nvidia found bugs in its virtual GPU software and the display driver that’s required for the graphics card to function.

Nvidia has a table showing the drivers for its different product lines across Windows and Linux, but it doesn’t really matter. It seems GeForce, Quadro, and Tesla drivers are vulnerable across Windows and Linux, so it’s best to update your graphics driver regardless.

In total, the company revealed 13 security vulnerabilities, five through the GPU display driver and eight through the vGPU software. Most sit in between 7 and 8 on CVSS 3.1 (Common Vulnerability Scoring System), which is an open standard for rating security vulnerabilities on a scale of 1 to 10.

Get your weekly teardown of the tech behind PC gaming
Check your inbox!

CVE‑2021‑1074 is one of the most pressing issues, with a base CVSS score of 7.5. This vulnerability shows up in the display driver installer, where an attacker with local system access can replace the installation files with malicious ones. On the other end, CVE‑2021‑1078 received a base score of 5.5, which shows a vulnerability in the kernel driver that could lead to a system crash.

Image used with permission by copyright holder

There’s also CVE‑2021‑1085 through the vGPU software (base score of 7.3), which opens the potential to write data to shared memory locations and manipulate it after validation. That could lead to escalation of privileges and denial of service.

If you just have an Nvidia graphics card, you don’t need to worry about the vGPU vulnerabilities. The vGPU software is built for the data center, allowing operators to share graphics card power across several virtual machines. Nvidia recommends updating your graphics card driver through the Nvidia driver download page and the vGPU software through the Nvidia licensing portal (if you have access to it).

geforce rtx 3090
Image used with permission by copyright holder

The vulnerabilities highlight the importance of updating your software and drivers regularly. Earlier this year, Nvidia fixed several vulnerabilities in its display driver, and it continues to push updates whenever vulnerabilities show up. The current batch of problems may lead to malicious code execution (ransomware, etc.), escalation of privileges, data disclosure, data corruption, and/or denial of service, so you should update your GPU driver as soon as possible.

All of the issues come through software, so it doesn’t matter which graphics card you have. Even with a last-gen or older GPU — a likely situation given the ongoing graphics card shortage — you still need to update your driver.

Editors' Recommendations

Jacob Roach
Lead Reporter, PC Hardware
Jacob Roach is the lead reporter for PC hardware at Digital Trends. In addition to covering the latest PC components, from…
CableMod’s adapters damaged up to $74K worth of Nvidia GPUs
Melted 12VHPWR connector made by CableMod for the RTX 4090.

CableMod's adapters were meant to fix the problem of melting connectors on Nvidia's top GPU, the RTX 4090, but it appears that things didn't go as planned. The Consumer Product Safety Commission has posted a notice that the CableMod 12VHPWR angled adapters are being recalled due to fire and burn hazards. More than 25,300 adapters are to be returned, and the affected customers are eligible for a full refund.

The connectors on the RTX 4090 have been melting ever since the GPU hit the shelves in late 2022, and so far, the only fix seems to lie in careful installation and picking the right PC case that can accommodate this monstrous card. CableMod's angled adapters showed a lot of promise, at least initially. Seeing as bending the cable can contribute to the overheating, an angled adapter should have been just the fix -- but unfortunately, the melting continued, even with the use of CableMod's solution.

Read more
Nvidia just fixed a major issue with its GPUs
The Nvidia RTX 4080 Super on a pink background.

If you've been unhappy with the performance of your graphics card lately, you might want to check out Nvidia's latest beta driver. This is a hotfix driver, which is pretty unusual for Nvidia, but it can be helpful if you've been dealing with micro-stuttering, both in games and on the desktop. The update addresses four issues in total, but to get it, you'll have to dig a little deeper than the standard path of updating your drivers.

Nvidia typically bundles bug fixes with its usual Game Ready drivers, as urgent hotfixes tend to be few and far between. However, this time, Nvidia chose not to wait any longer and pushed four updates for its GPU range. The new driver version, 551.46, may fix annoying stuttering issues.

Read more
GPU prices and availability (Q1 2024): How much are GPUs today?
An AMD Radeon RX 6500XT placed on a motherboard.

The GPU shortage is over, and gamers around the world can breathe a sigh of relief. For those in the market for one of the best graphics cards, we looked closely at graphics card prices and availability to determine where the GPU market is headed and the best time to buy.

If you're looking for a cheap GPU deal, now is the time to buy. Cards from AMD and Nvidia usually hover around the recommended list price, but some models are actually priced well below that, and the same goes for Intel GPUs.

Read more