Impact
NVIDIA GPU Display Driver for Linux contains a kernel mode vulnerability that allows an attacker to perform an out‑of‑bounds write in the driver’s memory. This flaw can lead to code execution, system denial of service, escalation of privileges, information disclosure, and data tampering. The CVE description only states that a successful exploit might enable these outcomes; it does not explicitly claim remote or local attack capability, so the impact is described in terms of potential exploitation of the vulnerable code.
Affected Systems
The vulnerability affects NVIDIA’s Linux GPU drivers, impacting all GeForce, RTX, Quadro, NVS, and Tesla product families. No specific driver revisions are listed, so all currently installed drivers that contain the vulnerable code are potentially affected.
Risk and Exploitability
The CVSS score of 6.7 indicates a medium severity vulnerability. EPSS data is not available and the issue is not listed in CISA’s KEV catalog, suggesting that exploitation is not yet widely observed. The likely attack surface is local or requires elevated privileges because the flawed code runs in kernel mode; however, the exact vector is not explicitly stated in the advisory, so the assessment is inferred from the nature of the vulnerability.
OpenCVE Enrichment