Impact
The vulnerability arises from improper validation of an array index within NVIDIA’s GPU Display Driver kernel mode layer. This weakness, classified as CWE-129 and CWE-1285, can be abused by an attacker to achieve code execution, denial of service, and privilege escalation, potentially leading to information disclosure and data tampering. The risk extends beyond a single user as it affects the kernel driver that governs GPU operations.
Affected Systems
The issue impacts NVIDIA GPU Display Driver releases for Windows and Linux affecting product families such as GeForce, RTX, Quadro, NVS, and Tesla. No specific version information is currently provided, so all affected driver builds should be considered at risk until a vendor‑issued fix is applied.
Risk and Exploitability
With a CVSS score of 6.7 the vulnerability is of moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, suggesting no known widespread exploitation yet. The likely attack vector is user‑level interaction with the driver, which could allow a malicious application or local attacker to trigger the unvalidated array access. Given the kernel‑mode nature of the flaw, successful exploitation could lead to full process compromise or system instability.
OpenCVE Enrichment