CVE-2025-23282
published 2025-10-10CVE-2025-23282: NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to escalate privileges. A successful exploit…
PriorityP433high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.16%
5.8th percentile
NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to escalate privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nvidia-graphics-drivers | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| debian | nvidia-graphics-drivers-legacy-340xx | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| debian | nvidia-graphics-drivers-legacy-390xx | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| debian | nvidia-graphics-drivers-tesla | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-418 | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-450 | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-460 | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-470 | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-535 | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-550 | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| debian | nvidia-open-gpu-kernel-modules | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| nvidia | geforce | — | — |
| nvidia | geforce | — | — |
| nvidia | geforce | — | — |
| nvidia | guest_driver | — | — |
| nvidia | guest_driver | — | — |
| nvidia | guest_driver | — | — |
| nvidia | guest_driver | — | — |
| nvidia | tesla | — | — |
| nvidia | tesla | — | — |
| nvidia | tesla | — | — |
| nvidia | virtual_gpu_manager | — | — |
| nvidia | virtual_gpu_manager | — | — |
| nvidia | virtual_gpu_manager | — | — |
| nvidia | virtual_gpu_manager | — | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.0HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kvm: NVIDIA Display Driver vulnerability due to race condition leading to escalate privileges
vendor_redhat·2025-10-10·CVSS 7.0
CVE-2025-23282 [HIGH] CWE-415 kvm: NVIDIA Display Driver vulnerability due to race condition leading to escalate privileges
kvm: NVIDIA Display Driver vulnerability due to race condition leading to escalate privileges
NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to escalate privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to escalate privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
Mitigation: Mitigation for this issue is either not available or the currently available options don't me
Debian
CVE-2025-23282: nvidia-graphics-drivers - NVIDIA Display Driver for Linux contains a vulnerability where an attacker might...
vendor_debian·2025·CVSS 7.0
CVE-2025-23282 [HIGH] CVE-2025-23282: nvidia-graphics-drivers - NVIDIA Display Driver for Linux contains a vulnerability where an attacker might...
NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to escalate privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
OSV
CVE-2025-23282: NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to escalate privileges
osv·2025-10-10·CVSS 7.0
CVE-2025-23282 [HIGH] CVE-2025-23282: NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to escalate privileges
NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to escalate privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
GHSA
GHSA-r7fp-qp23-pmqp: NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to escalate privileges
ghsa_unreviewed·2025-10-10
CVE-2025-23282 [HIGH] CWE-415 GHSA-r7fp-qp23-pmqp: NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to escalate privileges
NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to escalate privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
No detection rules found.
No public exploits indexed.
2025-10-10
Published