Impact
The vulnerability resides in the kernel mode layer of NVIDIA GPU display drivers for Windows and Linux. A local user can trigger a fault that exposes kernel stack contents, including return addresses and pointers. This disclosure enables attackers to reverse engineer the execution path and potentially inject code, leading to arbitrary code execution, denial of service, privilege escalation, and information disclosure.
Affected Systems
All NVIDIA GPU drivers listed by the CNA, including GeForce, RTX, Quadro, NVS, Tesla, and the Guest driver for both Windows and Linux platforms. Versions are not specified in the advisory, so any installed driver at the time of the advisory could be affected.
Risk and Exploitability
The CVSS base score of 7.8 indicates a high severity for this flaw, while the EPSS score is unavailable and it is not yet cataloged in CISA's Known Exploited Vulnerabilities register, suggesting no widespread active exploitation yet. Without a published patch, the risk remains elevated for systems running NVIDIA drivers that have not yet been updated; a local attacker who can load malicious code into the driver could potentially elevate privileges or take control of the system. Therefore, timely mitigation is essential.
OpenCVE Enrichment