Impact
A kernel‑mode layer in the NVIDIA GPU Display Driver contains an out‑of‑bounds read flaw (CWE‑125) that can be triggered by a user. Exploitation could allow the attacker to read arbitrary kernel‑heap memory, potentially leading to code execution, denial of service, privilege escalation, information disclosure, or data tampering.
Affected Systems
NVIDIA GeForce, RTX, Quadro, NVS, and Tesla GPUs running the affected Windows or Linux display driver. No specific driver versions are listed, so any installation of these products during the period covered by the advisory may be impacted.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog. The description states that a successful exploitation may lead to code execution, denial of service, privilege escalation, information disclosure, or data tampering. The vulnerability is triggered by a user interacting with the driver, implying a local execution context. Remote exploitation is not documented in the CVE record and, if possible, would be an inferred scenario rather than a confirmed one. The lack of listed mitigations in the advisory means an exploit is plausible, especially on systems with unused or compromised GPU drivers.
OpenCVE Enrichment