Impact
NVIDIA GPU Display Driver for Linux includes a flaw in the kernel mode layer where permissions on read‑only memory may not be preserved. If an attacker exploits this weakness, the consequences include code execution, denial of service, privilege escalation, information disclosure, and data tampering. The ability to execute code in kernel context allows full system control and the ability to manipulate or leak sensitive data.
Affected Systems
The vulnerability affects NVIDIA products that use the Linux GPU Display Driver, including GeForce, RTX, Quadro, NVS, Tesla, Guest driver, and the Virtual GPU Manager. Versions of the driver are currently unspecified; any installation using the affected kernel mode layer is potentially impacted.
Risk and Exploitability
The CVSS score of 7.8 places this problem in the High range, while the EPSS score is not available and it is not listed in the CISA KEV catalog. No explicit attack vector is disclosed, so the likely scenario is a local user with the ability to interact with the driver. An attacker would need to load the driver or otherwise trigger the permission loss in the kernel mode module. The risk remains significant due to the potential for full privilege escalation and code execution.
OpenCVE Enrichment