VDB

CVE-2018-3979

CVE-2018-3979 PUBLISHED

A remote denial-of-service vulnerability exists in the way the Nouveau Display Driver (the default Ubuntu Nvidia display driver) handles GPU shader execution. A specially crafted pixel shader can cause remote denial-of-service issues. An attacker can provide a specially crafted website to trigger this vulnerability. This vulnerability can be triggered remotely after the user visits a malformed website. No further user interaction is required. Vulnerable versions include Ubuntu 18.04 LTS (linux 4.15.0-29-generic x86_64), Nouveau Display Driver NV117 (vermagic: 4.15.0-29-generic SMP mod_unload).

EPSS 0.54% · 67.8th percentile

Risk Scores

EPSS Score
0.54%
67.8th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSxserver-xorg-video-nouveau-hwe-18.041:1.0.15-3~18.04.1, 0, 1:1.0.16-1~18.04.1
Ubuntu:20.04:LTSxserver-xorg-video-nouveau1:1.0.16-1, 0
Ubuntu:22.04:LTSxserver-xorg-video-nouveau1:1.0.17-1build1, 0, 1:1.0.17-2build1
Ubuntu:18.04:LTSxserver-xorg-video-nouveau0, *
Ubuntu:25.10xserver-xorg-video-nouveau0, *
Ubuntu:16.04:LTSxserver-xorg-video-nouveau-hwe-16.041:1.0.15-2~16.04.1, 1:1.0.12-2~16.04.1, 0
Ubuntu:16.04:LTSxserver-xorg-video-nouveau1:1.0.12-1build1, 1:1.0.11-1ubuntu3, *
Ubuntu:24.04:LTSxserver-xorg-video-nouveau1:1.0.17-2build1, 0, *

Timeline

  • Mar 26, 2019 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 28, 2022 EPSS Score
  • May 2, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 5, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 11, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›