Impact
The NVIDIA GPU Display Driver for Windows and Linux contains a kernel‑mode out‑of‑bounds read that can be triggered by a malicious user‑level process. A successful read may expose sensitive memory, cause a crash, or enable tampering with driver state, potentially leading to arbitrary code execution or full privilege escalation on the host system. The design flaw is recognized as a classic out‑of‑bounds buffer read (CWE‑125).
Affected Systems
All NVIDIA GPUs that use the GPU Display Driver, including GeForce, RTX, Quadro, NVS, Tesla, and the Virtual GPU Manager. The vulnerability is present in the driver on Windows and Linux platforms; no specific build or patch level is listed, so all current installations are potentially affected.
Risk and Exploitability
The CVSS base score of 7.8 indicates a high severity. No EPSS data is available, and the vulnerability is not yet listed in CISA’s KEV catalog, suggesting limited observed exploitation to date. The attack vector is inferred to be local, requiring the attacker to run malicious code on the target machine to load the driver. If the flaw is successfully exploited, the attacker could gain higher privileges, execute arbitrary code, or destabilize the system by causing a denial of service.
OpenCVE Enrichment