CVE-2025-23279

CWE-3675 documents5 sources
Severity
7.0HIGH
EPSS
0.0%
top 96.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 2
Latest updateAug 3

Description

NVIDIA .run Installer for Linux and Solaris contains a vulnerability where an attacker could use a race condition to escalate privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, denial of service, or data tampering.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Affected Packages7 packages

Debiannvidia-graphics-drivers< 535.261.03-1
Debiannvidia-graphics-drivers-tesla< 525.147.05-6
Debiannvidia-open-gpu-kernel-modules< 535.261.03-1
Debiannvidia-graphics-drivers-tesla-450< 450.248.02-4
Debiannvidia-graphics-drivers-tesla-460< 460.106.00-3

🔴Vulnerability Details

3
GHSA
GHSA-ppcc-852j-px73: NVIDIA2025-08-03
OSV
CVE-2025-23279: NVIDIA2025-08-02
CVEList
CVE-2025-23279: NVIDIA2025-08-02

📋Vendor Advisories

1
Debian
CVE-2025-23279: nvidia-graphics-drivers - NVIDIA .run Installer for Linux and Solaris contains a vulnerability where an at...2025
CVE-2025-23279 (HIGH CVSS 7) | NVIDIA .run Installer for Linux and | cvebase.io