CVE-2023-25516

CWE-190Integer Overflow5 documents5 sources
Severity
7.1HIGH
EPSS
0.0%
top 92.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 4

Description

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where an unprivileged user can cause an integer overflow, which may lead to information disclosure and denial of service.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:HExploitability: 1.8 | Impact: 5.2

Affected Packages8 packages

CVEListV5nvidia/gpu_display_driver_for_linuxAll versions prior to and including 15.2, 13.7, and 11.12, and all versions prior to and including the May 2023 release
NVDnvidia/gpu_display_driver13.013.7+2
Debiannvidia-graphics-drivers< 470.199.02-1+3
Debiannvidia-graphics-drivers-tesla< 525.125.06-1~deb12u1
Debiannvidia-open-gpu-kernel-modules< 525.125.06-1~deb12u1+2

🔴Vulnerability Details

3
OSV
CVE-2023-25516: NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where an unprivileged user can cause an integer overflow, which2023-07-04
GHSA
GHSA-9p48-jjr7-4fh3: NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where an unprivileged user can cause an integer overflow, which2023-07-04
CVEList
CVE-2023-25516: NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer, where an unprivileged user can cause an integer overflow, which2023-07-03

📋Vendor Advisories

1
Debian
CVE-2023-25516: nvidia-graphics-drivers - NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode ...2023
CVE-2023-25516 (HIGH CVSS 7.1) | NVIDIA GPU Display Driver for Linux | cvebase.io