Impact
The vulnerability is a kernel mode use‑after‑free in the NVIDIA GPU Display Driver for Windows and Linux. It allows a local user or process to trigger a memory corruption that can lead to arbitrary code execution, privilege escalation, denial of service, information disclosure, and data tampering. The weakness is a classic Use‑After‑Free, CWE‑416.
Affected Systems
Affected vendors include NVIDIA products such as GeForce, Tesla, RTX, Quadro, NVS, Guest Driver, and Virtual GPU Manager. All kernel mode components in these driver families are impacted. No specific version ranges are listed in the CNA data, so all current releases are potentially vulnerable until a patch is released.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity. EPSS is not available, so the current likelihood of exploitation is unknown, and the vulnerability is not present in the CISA KEV catalog. Based on the description, the likely attack vector is a local kernel exploitation via a privileged user or a process that has loaded the vulnerable driver. An attacker who succeeds could achieve complete control of the affected host.
OpenCVE Enrichment