Impact
The vulnerability is a kernel‑mode out‑of‑bounds write caused by mismatched memory buffers during event buffer setup. Successful exploitation can lead to code execution, denial of service, privilege escalation, information disclosure, and data tampering. The weakness is classified as CWE‑787, an unbounded write flaw.
Affected Systems
Affected systems include NVIDIA GeForce, Quadro, NVS, RTX, and Tesla graphics drivers, as well as the Guest driver and Virtual GPU Manager for Linux. The vendor list enumerates these products, but specific version ranges are not disclosed, so any installation of these drivers on a Linux host could be susceptible until a patch is applied.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity attack. EPSS is not available, so the current exploitation probability cannot be quantified, and the vulnerability is not listed in CISA KEV. The flaw requires a local user to inject crafted buffers into the driver; therefore the attack vector is likely local with elevated privileges. Without mitigation, an attacker could execute arbitrary kernel code and fully compromise the host.
OpenCVE Enrichment