CVE-2025-23282
published 2025-10-10CVE-2025-23282: NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to escalate privileges. A successful exploit…
PriorityP433high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.16%
5.9th percentile
NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to escalate privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nvidia-graphics-drivers | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| debian | nvidia-graphics-drivers-legacy-340xx | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| debian | nvidia-graphics-drivers-legacy-390xx | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| debian | nvidia-graphics-drivers-tesla | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-418 | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-450 | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-460 | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-470 | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-535 | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-550 | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| debian | nvidia-open-gpu-kernel-modules | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| nvidia | geforce | — | — |
| nvidia | geforce | — | — |
| nvidia | geforce | — | — |
| nvidia | guest_driver | — | — |
| nvidia | guest_driver | — | — |
| nvidia | guest_driver | — | — |
| nvidia | guest_driver | — | — |
| nvidia | tesla | — | — |
| nvidia | tesla | — | — |
| nvidia | tesla | — | — |
| nvidia | virtual_gpu_manager | — | — |
| nvidia | virtual_gpu_manager | — | — |
| nvidia | virtual_gpu_manager | — | — |
| nvidia | virtual_gpu_manager | — | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.0HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kvm: NVIDIA Display Driver vulnerability due to race condition leading to escalate privileges
vendor_redhat·2025-10-10·CVSS 7.0
CVE-2025-23282 [HIGH] CWE-415 kvm: NVIDIA Display Driver vulnerability due to race condition leading to escalate privileges
kvm: NVIDIA Display Driver vulnerability due to race condition leading to escalate privileges
NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to escalate privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to escalate privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
Mitigation: Mitigation for this issue is either not available or the currently available options don't me
Debian
CVE-2025-23282: nvidia-graphics-drivers - NVIDIA Display Driver for Linux contains a vulnerability where an attacker might...
vendor_debian·2025·CVSS 7.0
CVE-2025-23282 [HIGH] CVE-2025-23282: nvidia-graphics-drivers - NVIDIA Display Driver for Linux contains a vulnerability where an attacker might...
NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to escalate privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
OSV
CVE-2025-23282: NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to escalate privileges
osv·2025-10-10·CVSS 7.0
CVE-2025-23282 [HIGH] CVE-2025-23282: NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to escalate privileges
NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to escalate privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
GHSA
GHSA-r7fp-qp23-pmqp: NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to escalate privileges
ghsa_unreviewed·2025-10-10
CVE-2025-23282 [HIGH] CWE-415 GHSA-r7fp-qp23-pmqp: NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to escalate privileges
NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to escalate privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-10-10
Published