Impact
An out‑of‑bounds read in the kernel‑mode layer of NVIDIA GPU Display Driver for Windows and Linux enables an attacker to read outside the allocated buffer, a flaw classified as CWE‑125. This defect can be exploited to potentially cause code execution, privilege escalation, denial of service, information disclosure, and data tampering.
Affected Systems
The vulnerability impacts NVIDIA GPU drivers on Windows and Linux for GeForce, RTX, Quadro, NVS, and Tesla series. Specific affected driver version information is not provided in the public disclosure.
Risk and Exploitability
The CVSS score of 6.7 indicates medium severity, while no EPSS data is available and the issue is not listed in the CISA KEV catalog. Exploitation likely requires local access to the device driver; a successful out‑of‑bounds read could be leveraged into code execution or privilege escalation. The combination of confidentiality and integrity implications keeps the risk significant despite uncertain exploitation conditions.
OpenCVE Enrichment