Impact
The NVIDIA GPU Display Driver for Windows and Linux contains an integer overflow vulnerability in its kernel mode layer that can lead to an out‑of‑bounds write into GPU memory. A successful exploit could allow an attacker to execute arbitrary code, cause a denial of service, elevate privileges, disclose information, or tamper with data. The weakness is categorized as CWE‑190, indicating an unsigned or signed integer overflow. The impact scope ranges from local escalation to full system compromise depending on the attacker’s initial access level.
Affected Systems
The vulnerability affects all NVIDIA GPU drivers for GeForce, Guest Driver, RTX, Quadro, NVS, and Tesla families on both Windows and Linux platforms. No specific version information is provided, so all current releases of these drivers are potentially impacted until a patch is applied.
Risk and Exploitability
The CVSS base score of 7.8 places this bug in the high‑severity range. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no confirmed widespread exploitation yet. The likely attack vector is inferred to be local via a user with GPU access or through remote code execution if the driver is exposed over network interfaces; however, the exact prerequisites for exploitation are not detailed in the description.
OpenCVE Enrichment