CVE-2025-23300
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-10-23

Last updated on: 2025-10-27

Assigner: NVIDIA Corporation

Description
NVIDIA Display Driver for Linux contains a vulnerability in the kernel driver, where a user could cause a null pointer dereference by allocating a specific memory resource. A successful exploit of this vulnerability might lead to denial of service.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-10-23
Last Modified
2025-10-27
Generated
2026-05-06
AI Q&A
2025-10-23
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 5 associated CPEs
Vendor Product Version / Range
nvidia display_driver 535.274.02
nvidia display_driver 580.95.05
nvidia cloud_gaming *
nvidia vgpu *
nvidia display_driver 570.195.03
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

CVE-2025-23300 is a medium severity vulnerability in the NVIDIA Display Driver for Linux kernel driver. It involves a null pointer dereference that can be triggered by a user allocating a specific memory resource. Exploiting this vulnerability can cause the system to crash or become unavailable, resulting in a denial of service (DoS). [1]


How can this vulnerability impact me? :

This vulnerability can impact you by causing a denial of service condition on systems running the affected NVIDIA Display Driver for Linux. An attacker with low privileges and local access can trigger a null pointer dereference, leading to system instability or crash, affecting availability but not confidentiality or integrity. [1]


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability, you should immediately upgrade your NVIDIA Display Driver for Linux to the patched versions released in October 2025. The fixed driver versions are 580.95.05 (R580), 570.195.03 (R570), and 535.274.02 (R535). These updates address the null pointer dereference vulnerability and are available through the NVIDIA Driver Downloads page. Additionally, if you use NVIDIA vGPU or Cloud Gaming software on Linux, update those guest drivers and virtual GPU managers via the NVIDIA Licensing Portal. Upgrading to these latest versions will reduce the risk of denial of service caused by this vulnerability. [1]


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart