Impact
The NVIDIA GPU Display Driver for Windows and Linux contains a kernel mode layer vulnerability where an attacker could cause an integer underflow. A successful exploit of this flaw could result in code execution, denial of service, escalation of privileges, information disclosure, and data tampering. The description indicates an integer underflow that may lead to arbitrary memory corruption within the driver’s kernel space.
Affected Systems
Affected systems include NVIDIA GeForce, RTX, Quadro, NVS, Tesla GPUs, and the NVIDIA Virtual GPU Manager, across both Windows and Linux operating systems. No specific driver versions are listed, so all current versions that include the kernel mode component are potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.8 classifies this vulnerability as high severity, indicating significant risk to memory integrity and privilege boundaries. The EPSS score is not available, so the exact likelihood of exploitation remains unknown, and the vulnerability is not listed in the CISA KEV catalog. Based on the description of an integer underflow in a kernel‑mode driver, the most likely exploitation path involves triggering the driver’s kernel mode path with crafted data from software running on the same host. An attacker who can deliver malicious payloads to the GPU device could exploit the flaw to execute arbitrary code, crash the driver, or gain elevated privileges, as inferred from the potential impact statements provided. The attack vector is inferred to be local or privileged, as remote exploitation would require exposure of driver interfaces to external actors, which is not explicitly documented.
OpenCVE Enrichment