Impact
NVIDIA GPU Display Driver for Windows and Linux contains a firmware flaw where an uninitialized pointer can be accessed by an attacker. This leads to possible code execution, denial of service, privilege escalation, information disclosure, and data tampering. The weakness is classified as CWE‑824, indicating that a program can access an object that has not been properly initialized.
Affected Systems
All NVIDIA GPU driver families—GeForce, RTX, Quadro, NVS, Tesla, and Virtual GPU Manager—are potentially affected, regardless of operating system. No specific affected firmware versions were supplied, implying the vulnerability may span multiple driver releases until patched.
Risk and Exploitability
The CVSS score of 7.8 signals high severity, but the EPSS score is not provided, making the probability of real-world exploitation unclear. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is local access to the GPU or privileged firmware execution. An attacker with sufficient access could exploit the uninitialized pointer to achieve arbitrary code execution or cause a denial of service on the host system.
OpenCVE Enrichment