Impact
The NVIDIA GPU Display Driver for Linux contains a flaw in the kernel mode layer where an unprivileged user can trigger improper release of memory resources. This mismanagement can leave a mapping accessible after the underlying memory is reused, potentially enabling arbitrary code execution, denial of service, privilege escalation, information disclosure, and data tampering, which compromise confidentiality, integrity, and availability.
Affected Systems
Affected systems include NVIDIA GPUs on Linux that use the GeForce, Guest Driver, RTX, Quadro, NVS, and Tesla product lines. The CNA data does not list specific driver versions, so administrators should verify the installed driver revision and apply updates accordingly.
Risk and Exploitability
The CVSS score of 7.8 conveys high severity. No EPSS score is available, so the current exploitation probability cannot be quantified, and the vulnerability is not referenced in the CISA KEV catalog. The likely attack scenario is that an unprivileged local user can exploit the kernel mode vulnerability to cause improper memory release, potentially executing code or escalating privileges on the host.
OpenCVE Enrichment