CVE-2025-23282

HIGH

NVIDIA Display Driver - Privilege Escalation

Title source: llm
STIX 2.1

Description

NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to escalate privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.

Scores

CVSS v3 7.0
EPSS 0.0002
EPSS Percentile 3.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-415
Status published
Products (17)
NVIDIA/GeForce All driver versions prior to 535.274.02
NVIDIA/GeForce All driver versions prior to 570.195.03
NVIDIA/GeForce All driver versions prior to 580.95.05
NVIDIA/Guest driver 535.261.03(All versions prior to and including vGPU 16.11)
NVIDIA/Guest driver 570.172.08(All versions prior to and including vGPU 18.4)
NVIDIA/Guest driver 580.82.07(All versions prior to and including vGPU 19.1)
NVIDIA/Guest driver 580.82.07(All versions up to and including the August 2025 release)
NVIDIA/NVIDIA RTX, Quadro, NVS All driver versions prior to 535.274.02
NVIDIA/NVIDIA RTX, Quadro, NVS All driver versions prior to 570.195.03
NVIDIA/NVIDIA RTX, Quadro, NVS All driver versions prior to 580.95.05
... and 7 more
Published Oct 10, 2025
Tracked Since Feb 18, 2026