CVE-2025-23300
published 2025-10-23CVE-2025-23300: NVIDIA Display Driver for Linux contains a vulnerability in the kernel driver, where a user could cause a null pointer dereference by allocating a specific…
PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.14%
3.6th percentile
NVIDIA Display Driver for Linux contains a vulnerability in the kernel driver, where a user could cause a null pointer dereference by allocating a specific memory resource. A successful exploit of this vulnerability might lead to denial of service.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nvidia-graphics-drivers | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| debian | nvidia-graphics-drivers-legacy-340xx | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| debian | nvidia-graphics-drivers-legacy-390xx | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| debian | nvidia-graphics-drivers-tesla | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-418 | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-450 | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-460 | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-470 | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-535 | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-550 | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| debian | nvidia-open-gpu-kernel-modules | < nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) | nvidia-graphics-drivers-tesla 525.147.05-6 (bookworm) |
| nvidia | geforce | — | — |
| nvidia | geforce | — | — |
| nvidia | geforce | — | — |
| nvidia | guest_driver | — | — |
| nvidia | guest_driver | — | — |
| nvidia | guest_driver | — | — |
| nvidia | guest_driver | — | — |
| nvidia | tesla | — | — |
| nvidia | tesla | — | — |
| nvidia | tesla | — | — |
| nvidia | virtual_gpu_manager | — | — |
| nvidia | virtual_gpu_manager | — | — |
| nvidia | virtual_gpu_manager | — | — |
| nvidia | virtual_gpu_manager | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
nvidia-display-driver: NVIDIA Display Driver Null pointer dereference
vendor_redhat·2025-10-23·CVSS 5.5
CVE-2025-23300 [MEDIUM] CWE-476 nvidia-display-driver: NVIDIA Display Driver Null pointer dereference
nvidia-display-driver: NVIDIA Display Driver Null pointer dereference
NVIDIA Display Driver for Linux contains a vulnerability in the kernel driver, where a user could cause a null pointer dereference by allocating a specific memory resource. A successful exploit of this vulnerability might lead to denial of service.
A vulnerability exists in the Linux kernel module of the NVIDIA Display Driver. A local, low-privileged user may allocate a specifically crafted memory resource, which triggers a NULL pointer dereference in the driver
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: rhela
Debian
CVE-2025-23300: nvidia-graphics-drivers - NVIDIA Display Driver for Linux contains a vulnerability in the kernel driver, w...
vendor_debian·2025·CVSS 5.5
CVE-2025-23300 [MEDIUM] CVE-2025-23300: nvidia-graphics-drivers - NVIDIA Display Driver for Linux contains a vulnerability in the kernel driver, w...
NVIDIA Display Driver for Linux contains a vulnerability in the kernel driver, where a user could cause a null pointer dereference by allocating a specific memory resource. A successful exploit of this vulnerability might lead to denial of service.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-3vrr-h3vm-h333: NVIDIA Display Driver for Linux contains a vulnerability in the kernel driver, where a user could cause a null pointer dereference by allocating a spe
ghsa_unreviewed·2025-10-23
CVE-2025-23300 [MEDIUM] CWE-476 GHSA-3vrr-h3vm-h333: NVIDIA Display Driver for Linux contains a vulnerability in the kernel driver, where a user could cause a null pointer dereference by allocating a spe
NVIDIA Display Driver for Linux contains a vulnerability in the kernel driver, where a user could cause a null pointer dereference by allocating a specific memory resource. A successful exploit of this vulnerability might lead to denial of service.
OSV
CVE-2025-23300: NVIDIA Display Driver for Linux contains a vulnerability in the kernel driver, where a user could cause a null pointer dereference by allocating a spe
osv·2025-10-23·CVSS 5.5
CVE-2025-23300 [MEDIUM] CVE-2025-23300: NVIDIA Display Driver for Linux contains a vulnerability in the kernel driver, where a user could cause a null pointer dereference by allocating a spe
NVIDIA Display Driver for Linux contains a vulnerability in the kernel driver, where a user could cause a null pointer dereference by allocating a specific memory resource. A successful exploit of this vulnerability might lead to denial of service.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-10-23
Published