Impact
The vulnerability lies in NVIDIA’s GPU Display Driver for Windows and Linux, specifically in the kernel‑mode layer where input validation is insufficient. This flaw permits an attacker to manipulate kernel memory, potentially enabling arbitrary code execution, denial of service, privilege escalation, information disclosure, and data tampering. The weakness is a classic input validation error, identified as CWE‑20.
Affected Systems
Angled systems include all NVIDIA graphics families—GeForce, RTX, Quadro, NVS, and Tesla—across both Windows and Linux platforms. The public advisory does not specify affected driver releases, so any current GPU display driver installation is considered vulnerable until a vendor‑issued patch is applied.
Risk and Exploitability
The CVSS rating of 6.7 indicates a moderate severity, yet the potential for kernel‑level code execution elevates the risk for local attackers. The EPSS score is not provided, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation data as of now. Based on the description, it is inferred that an attacker would need to deliver crafted input to the kernel driver, likely via a privileged process or a compromised application with sufficient kernel access, to trigger the flaw.
OpenCVE Enrichment