Impact
The vulnerability is a flaw in the kernel mode layer of the NVIDIA GPU Display Driver for Linux that allows an unprivileged user to bypass an authorization check and modify privileged configuration settings. This bypass can enable an attacker to execute arbitrary code, perform denial of service or tamper with data. The effect is a complete escalation of privileges and potential compromise of system confidentiality, integrity, and availability.
Affected Systems
Affected products include various NVIDIA GPU families such as GeForce, RTX, Quadro, NVS, Tesla, and the Virtual GPU Manager. No specific version information is provided in the publicly available data, so all versions of these drivers are potentially impacted.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score is not available, so the precise likelihood of exploitation is unknown, but the vulnerability is not yet listed in the CISA KEV catalog. A local, unprivileged user who can interact with the driver can exploit the authorization bypass to gain higher privileges and potentially execute arbitrary code. The attack vector is likely local, originating from user‑mode processes that interact with the GPU driver. The exploit path involves a trusted kernel module and manipulated device files, which presents a moderate to high difficulty for attackers who can gain a user session on the affected system.
OpenCVE Enrichment