Impact
The vulnerability lies in NVIDIA’s Linux display driver’s Multi‑Instance GPU (MIG) partition management subsystem. During initialization, the driver fails to secure memory‑routing resources, which can result in data corruption or a system hang when a partition is reconfigured. A successful exploit can therefore lead to a denial of service. This weakness is classified as CWE‑1188, an insecure default configuration that allows improper resource handling.
Affected Systems
The issue affects NVIDIA graphics stacks running on Linux, including GeForce, RTX, Quadro, NVS, Tesla, and the Virtual GPU Manager. The vulnerability applies to the driver packages distributed for these GPUs; specific version numbers are not disclosed in the provided information.
Risk and Exploitability
With a CVSS score of 6.5, the severity is moderate. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, implying limited or no known exploitation in the wild. Attack details are not described in the advisory; it is inferred that exploitation would likely require elevated privileges or local access to load or reconfigure the driver, making the threat vector likely local rather than remote.
OpenCVE Enrichment