Impact
The NVIDIA Linux GPU Display Driver contains a type‑confusion vulnerability in the NGX updater caused by an outdated embedded cryptographic library. If successfully exploited, an attacker could achieve code execution, denial of service, information disclosure, or data tampering. This weakness can potentially allow privileged or local users to manipulate GPU driver behavior or compromise host processes.
Affected Systems
Affects NVIDIA Linux GPU drivers used in GeForce, RTX, Quadro, NVS, and Tesla product lines. Specific affected driver versions are not listed, so any release that includes the NGX updater is likely vulnerable until a fix is applied.
Risk and Exploitability
The CVSS v3 score of 7.8 indicates high severity, but no EPSS data is available, and the vulnerability is not listed in the CISA KEV. The attack vector is likely local, as the NGX updater runs within the driver context; remote exploitation would require additional steps such as a driver exploitation chain. Because the weakness is a type confusion in a cryptographic routine, exploitation would need precise conditions, so the risk is significant but exploitation is non‑trivial.
OpenCVE Enrichment