PatchSiren cyber security CVE debrief
CVE-2017-0318 Freebsd CVE debrief
CVE-2017-0318 is a medium-severity vulnerability in NVIDIA Linux GPU Display Driver kernel-mode handling. The issue is caused by improper validation of an input parameter and can result in a denial of service on the affected system. The official NVD record maps the vulnerable CPE to NVIDIA GPU driver software and classifies the weakness as CWE-20 (Improper Input Validation).
- Vendor
- Freebsd
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-15
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-15
- Advisory updated
- 2026-05-13
Who should care
System administrators, workstation owners, and platform teams running NVIDIA GPU display drivers on Linux should review this issue, especially where untrusted local users or local code execution is possible.
Technical summary
The NVD CVE record describes a local attack surface (CVSS:3.0 AV:L) with low attack complexity and low privileges required, no user interaction, and high availability impact. The vulnerability is in a kernel mode layer handler and stems from insufficient validation of an input parameter. The recorded outcome is denial of service rather than data disclosure or integrity impact. The official NVD metadata also includes vendor advisory reference 4398 from NVIDIA.
Defensive priority
Medium priority. It is not marked as KEV, but it can impact system availability on affected NVIDIA driver installations and should be reviewed during normal patch management.
Recommended defensive actions
- Check whether any Linux systems in your environment use NVIDIA GPU display drivers.
- Review the NVIDIA vendor advisory referenced by NVD for affected products and remediation guidance.
- Apply vendor-provided updates or mitigations as soon as they are validated in your environment.
- Limit local code execution and untrusted local access on systems where patching is delayed.
- Monitor affected hosts for unexpected display-driver crashes or service disruption after any exposure to local untrusted code.
Evidence notes
Source corpus describes the flaw as affecting NVIDIA Linux GPU Display Driver and states that improper validation of an input parameter may cause a denial of service. The NVD record links the vulnerability to NVIDIA GPU driver CPEs and assigns CWE-20 with CVSS vector CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. The provided vendor metadata names FreeBSD, but that conflicts with the CVE description and NVD CPE data; this debrief follows the official CVE/NVD record.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-0318 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-0318
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-0318 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-0318
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.