CVE-2025-23279
published 2025-08-02CVE-2025-23279: NVIDIA .run Installer for Linux and Solaris contains a vulnerability where an attacker could use a race condition to escalate privileges. A successful exploit…
PriorityP432high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.10%
0.9th percentile
NVIDIA .run Installer for Linux and Solaris contains a vulnerability where an attacker could use a race condition to escalate privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, denial of service, or data tampering.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nvidia-graphics-drivers | < nvidia-graphics-drivers 535.261.03-1 (bookworm) | nvidia-graphics-drivers 535.261.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-legacy-340xx | < nvidia-graphics-drivers 535.261.03-1 (bookworm) | nvidia-graphics-drivers 535.261.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-legacy-390xx | < nvidia-graphics-drivers 535.261.03-1 (bookworm) | nvidia-graphics-drivers 535.261.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla | < nvidia-graphics-drivers 535.261.03-1 (bookworm) | nvidia-graphics-drivers 535.261.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-418 | < nvidia-graphics-drivers 535.261.03-1 (bookworm) | nvidia-graphics-drivers 535.261.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-450 | < nvidia-graphics-drivers 535.261.03-1 (bookworm) | nvidia-graphics-drivers 535.261.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-460 | < nvidia-graphics-drivers 535.261.03-1 (bookworm) | nvidia-graphics-drivers 535.261.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-470 | < nvidia-graphics-drivers 535.261.03-1 (bookworm) | nvidia-graphics-drivers 535.261.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-535 | < nvidia-graphics-drivers 535.261.03-1 (bookworm) | nvidia-graphics-drivers 535.261.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-550 | < nvidia-graphics-drivers 535.261.03-1 (bookworm) | nvidia-graphics-drivers 535.261.03-1 (bookworm) |
| debian | nvidia-open-gpu-kernel-modules | < nvidia-graphics-drivers 535.261.03-1 (bookworm) | nvidia-graphics-drivers 535.261.03-1 (bookworm) |
| nvidia | gpu_display_drivers | — | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.0HIGH
vendor_debian7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2025-23279: nvidia-graphics-drivers - NVIDIA .run Installer for Linux and Solaris contains a vulnerability where an at...
vendor_debian·2025·CVSS 7.0
CVE-2025-23279 [HIGH] CVE-2025-23279: nvidia-graphics-drivers - NVIDIA .run Installer for Linux and Solaris contains a vulnerability where an at...
NVIDIA .run Installer for Linux and Solaris contains a vulnerability where an attacker could use a race condition to escalate privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, denial of service, or data tampering.
Scope: local
bookworm: resolved (fixed in 535.261.03-1)
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-ppcc-852j-px73: NVIDIA
ghsa_unreviewed·2025-08-03
CVE-2025-23279 [HIGH] CWE-367 GHSA-ppcc-852j-px73: NVIDIA
NVIDIA .run Installer for Linux and Solaris contains a vulnerability where an attacker could use a race condition to escalate privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, denial of service, or data tampering.
OSV
CVE-2025-23279: NVIDIA
osv·2025-08-02·CVSS 7.0
CVE-2025-23279 [HIGH] CVE-2025-23279: NVIDIA
NVIDIA .run Installer for Linux and Solaris contains a vulnerability where an attacker could use a race condition to escalate privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, denial of service, or data tampering.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-02
Published