Impact
An out‑of‑bounds write in the kernel mode layer of NVIDIA’s GPU Display Driver for Linux can allow a locally privileged attacker to execute arbitrary code. The vulnerability may lead to denial of service, elevation of privileges, information disclosure, and data tampering. This is a classic CWE‑787 buffer overflow scenario where unchecked memory writes compromise integrity and confidentiality of the operating system.
Affected Systems
The flaw affects all NVIDIA graphics products that use the driver on Linux, including GeForce, RTX, Quadro, NVS, and Tesla GPUs. Specific affected driver versions are not listed in the available data; any installation that relies on the vulnerable driver build is potentially impacted.
Risk and Exploitability
The CVSS score of 6.7 signals a moderate severity vulnerability. No EPSS score is available and the issue is not listed in the CISA KEV catalog, suggesting limited widespread exploitation at this time. The attack vector is likely local, requiring the ability to load or interact with the NVIDIA kernel module; it would not be exploitable over the network without additional conditions.
OpenCVE Enrichment