CVE-2025-23332

MEDIUM

NVIDIA Display Driver - Use After Free

Title source: llm
STIX 2.1

Description

NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where an attacker might be able to trigger a null pointer deference. A successful exploit of this vulnerability might lead to denial of service.

Scores

CVSS v3 5.0
EPSS 0.0003
EPSS Percentile 10.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-476
Status published
Products (16)
NVIDIA/GeForce All driver versions prior to 535.274.02
NVIDIA/GeForce All driver versions prior to 570.195.03
NVIDIA/GeForce All driver versions prior to 580.95.05
NVIDIA/Guest driver 535.261.03(All versions prior to and including vGPU 16.11)
NVIDIA/Guest driver 570.172.08(All versions prior to and including vGPU 18.4)
NVIDIA/Guest driver 580.82.07(All versions prior to and including vGPU 19.1)
NVIDIA/Guest driver 580.82.07(All versions up to and including the August 2025 release)
NVIDIA/NVIDIA RTX, Quadro, NVS All driver versions prior to 535.274.02
NVIDIA/NVIDIA RTX, Quadro, NVS All driver versions prior to 570.195.03
NVIDIA/NVIDIA RTX, Quadro, NVS All driver versions prior to 580.95.05
... and 6 more
Published Oct 23, 2025
Tracked Since Feb 18, 2026