Impact
The vulnerability resides in NVIDIA’s GPU Display Driver for Windows and Linux, specifically within the kernel mode layer. A flawed numeric type conversion can be engineered by a malicious actor to execute arbitrary code, obtain elevated privileges, crash the system, exfiltrate data, or tamper with information. The exploit turns a simple type‑mismatch into a full privilege escalation and potential denial of service.
Affected Systems
Affected are all NVIDIA GPU products announced under the GeForce, RTX, Quadro, NVS, Tesla, and Virtual GPU Manager lines. The driver package applies to both Windows and Linux operating systems. Specific version details are not supplied by the CNA or advisory references, so any driver installation that predates the vendor’s latest security release is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity attack path. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The kernel mode context suggests a local privilege escalation vector, likely requiring a user with local access to load the vulnerable driver. Because the description states a conversion error in kernel space, the attacker would need to execute the malformed input through driver interaction, which is inferred rather than explicitly documented. If successful, a local adversary could achieve full system compromise or cause the device to fail.
OpenCVE Enrichment