Impact
NVIDIA GPU Display Driver for Linux contains a format string flaw that an attacker could exploit to achieve code execution, privilege escalation, data tampering, denial of service, and information disclosure, as detailed in the vendor’s description.
Affected Systems
The issue affects NVIDIA GeForce, RTX, Quadro, NVS, and Tesla GPUs running their Linux display driver. The specific driver versions are not listed in the available information, so any Linux system using this driver family could be impacted.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability, but the EPSS score is unavailable, and the vulnerability is not present in the CISA KEV catalog. Based on the description, the likely attack vector is local, requiring a user to invoke the vulnerable driver component. The vulnerability relies on an improper format string handler (CWE‑134), which can allow arbitrary code execution when an attacker supplies crafted input to the driver. The high severity and local nature suggest a considerable risk to affected systems if the driver is not updated promptly.
OpenCVE Enrichment