Impact
NVIDIA GPU Display Driver for Windows and Linux contains an out‑of‑bounds array access in its kernel‑mode layer. Based on the description, a user who can load the driver can trigger the flaw, potentially enabling arbitrary code execution at kernel privilege level, privilege escalation, denial of service, information disclosure, or tampering with data. The impact is local but can lead to full system compromise if exploited successfully.
Affected Systems
All NVIDIA GPU Display Drivers that support GeForce, RTX, Quadro, NVS, Tesla and Virtual GPU Manager product lines are affected. The precise version details are not published, but the issue resides in the kernel‑mode component common to all drivers on both Windows and Linux platforms.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity level. No EPSS probability score is available and the vulnerability is not yet catalogued in the CISA KEV list, suggesting limited or unconfirmed exploitation activity. Based on the description, the likely attack vector is local, requiring the ability to run code with the driver’s privileges. If exploited, the impact ranges from crashing the system to executing arbitrary code with kernel privileges, making vigilance and timely mitigation essential.
OpenCVE Enrichment