CVE-2025-23282
BaseFortify
Publication date: 2025-10-10
Last updated on: 2025-10-14
Assigner: NVIDIA Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| nvidia | display_driver | 535.274.02 |
| nvidia | display_driver | 580.95.05 |
| nvidia | cloud_gaming | * |
| nvidia | vgpu | * |
| nvidia | display_driver | 570.195.03 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-415 | The product calls free() twice on the same memory address. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the NVIDIA Display Driver for Linux and involves a race condition that an attacker might exploit to escalate privileges. If successfully exploited, it could allow the attacker to execute code, escalate their privileges, tamper with data, cause denial of service, and disclose information.
How can this vulnerability impact me? :
The impact of this vulnerability includes potential unauthorized code execution, privilege escalation, data tampering, denial of service, and information disclosure, which could compromise system security and stability.