Impact
The vulnerability resides in the firmware of NVIDIA's Virtual GPU Manager for Linux. The flaw is an out‑of‑bounds read that, if successfully exploited, could allow an attacker to read adjacent memory. An attacker might leverage this read to obtain sensitive data or gain foothold for further attack. In the most severe scenario, the exploitation could lead to arbitrary code execution, escalation of privileges, and data tampering. The weakness aligns with CWE‑125.
Affected Systems
The affected product is NVIDIA Virtual GPU Manager for Linux. All current releases are impacted; specific version data is not supplied by the CNA. The vulnerability affects Linux hosts that run the vGPU Manager.
Risk and Exploitability
The CVSS base score is 7.8, reflecting substantial impact. The EPSS score is not available, so the current probability of exploitation cannot be quantified. The vulnerability is not listed in CISA's KEV catalog, indicating no known active exploitation. Attackers require local or remote access to the vGPU firmware; the exact attack vector is not detailed in the description, thus it is inferred that local privilege escalation or VM escape may be required.
OpenCVE Enrichment