cbcvebase.

Nvidia Tesla vulnerabilities

29 known vulnerabilities affecting nvidia/tesla.

Total CVEs
29
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH18MEDIUM9LOW2

Vulnerabilities

Page 1 of 2
CVE-2026-24187P3HIGHCVSS 8.8vAll driver versions prior to 595.71.05vAll driver versions prior to 580.159.03+1 more2026-05-26
CVE-2026-24187 [HIGH] CWE-416 CVE-2026-24187: NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-f NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.
nvd
CVE-2026-48594P3HIGH≥ 0.6.0, < 1.18.32026-07-10
CVE-2026-48594 [HIGH] CWE-409 Tesla has decompression bomb on response body Tesla has decompression bomb on response body ### Summary Any Tesla client pipeline that includes `Tesla.Middleware.DecompressResponse` or `Tesla.Middleware.Compression` eagerly decompresses HTTP response bodies with no size limit. A server under attacker control (or reached via a redirect) can return a tiny gzip-encoded payload that expands into gigabytes of BEAM heap, crashing or freezing the calling process. Stackin
ghsa
CVE-2026-48597P3HIGH≥ 1.3.0, < 1.18.32026-07-10
CVE-2026-48597 [HIGH] CWE-770 Tesla vulnerable to atom exhaustion via untrusted URL scheme Tesla vulnerable to atom exhaustion via untrusted URL scheme ### Summary In the Mint adapter for the Tesla HTTP client library, `Tesla.Adapter.Mint.open_conn/2` passes the URL scheme of every outgoing request through `String.to_atom/1` with no allow-list validation. Because BEAM atoms are permanent (never garbage-collected) and the atom table is bounded at roughly 1,048,576 entries, an attacker who can v
ghsa
CVE-2026-48595P3HIGH≥ 0.6.0, < 1.18.32026-07-10
CVE-2026-48595 [HIGH] CWE-178 Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering Tesla: Authorization header leaks on cross-origin redirect via case-sensitive filtering ### Summary `Tesla.Middleware.FollowRedirects` is meant to strip the `Authorization` header when following a cross-origin redirect, but performs the check with a case-sensitive comparison against the lowercase string `"authorization"`. Because Tesla preserves header keys exactly as supplied
ghsa
CVE-2026-24193P3HIGHCVSS 7.8vAll driver versions prior to 580.159.03vAll driver versions prior to 535.309.01+2 more2026-05-26
CVE-2026-24193 [HIGH] CWE-787 CVE-2026-24193: NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could cause a NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.
nvd
CVE-2026-24190P3HIGHCVSS 7.8vAll driver versions prior to 595.71.05vAll driver versions prior to 580.159.03+4 more2026-05-26
CVE-2026-24190 [HIGH] CWE-862 CVE-2026-24190: NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause improper access to GPU resources. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.
nvd
CVE-2025-33220P3HIGHCVSS 7.8vAll driver versions prior to 590.48.01vAll driver versions prior to 580.126.09+2 more2026-01-28
CVE-2025-33220 [HIGH] CWE-416 CVE-2025-33220: NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest co NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause heap memory access after the memory is freed. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, or information disclosure.
nvd
CVE-2025-33219P3HIGHCVSS 7.8vAll driver versions prior to 590.48.01vAll driver versions prior to 580.126.09+2 more2026-01-28
CVE-2025-33219 [HIGH] CWE-190 CVE-2025-33219: NVIDIA Display Driver for Linux contains a vulnerability in the NVIDIA kernel module where an attack NVIDIA Display Driver for Linux contains a vulnerability in the NVIDIA kernel module where an attacker could cause an integer overflow or wraparound. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, or information disclosure.
nvd
CVE-2026-24192P3HIGHCVSS 7.8vAll driver versions prior to 595.71.05vAll driver versions prior to 580.159.03+1 more2026-05-26
CVE-2026-24192 [HIGH] CWE-681 CVE-2026-24192: NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause an incorrect NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause an incorrect conversion between numeric types, leading to a heap buffer overflow. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.
nvd
CVE-2025-33218P3HIGHCVSS 7.8vAll driver versions prior to 591.59vAll driver versions prior to 582.16+2 more2026-01-28
CVE-2025-33218 [HIGH] CWE-190 CVE-2025-33218: NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sy NVIDIA GPU Display Driver for Windows contains a vulnerability in the kernel mode layer (nvlddmkm.sys), where an attacker could cause an integer overflow. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, or information disclosure.
nvd
CVE-2025-33217P3HIGHCVSS 7.8vAll driver versions prior to 591.59vAll driver versions prior to 582.16+2 more2026-01-28
CVE-2025-33217 [HIGH] CWE-416 CVE-2025-33217: NVIDIA Display Driver for Windows contains a vulnerability where an attacker could trigger a use aft NVIDIA Display Driver for Windows contains a vulnerability where an attacker could trigger a use after free. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
nvd
CVE-2025-23347P3HIGHCVSS 7.8vAll driver versions prior to 581.42vAll driver versions prior to 573.762025-10-23
CVE-2025-23347 [HIGH] CWE-276 CVE-2025-23347: NVIDIA Project G-Assist contains a vulnerability where an attacker might be able to escalate permiss NVIDIA Project G-Assist contains a vulnerability where an attacker might be able to escalate permissions. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
nvd
CVE-2026-24194P3HIGHCVSS 7.8vAll driver versions prior to 595.71.05vAll driver versions prior to 580.159.03+1 more2026-05-26
CVE-2026-24194 [HIGH] CWE-281 CVE-2026-24194: NVIDIA Display Driver for Linux contains a vulnerability in a kernel mode layer handler, where a use NVIDIA Display Driver for Linux contains a vulnerability in a kernel mode layer handler, where a user could cause improper permission handling. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.
nvd
CVE-2026-24191P3HIGHCVSS 7.8vAll driver versions prior to 596.36vAll driver versions prior to 582.53+1 more2026-05-26
CVE-2026-24191 [HIGH] CWE-367 CVE-2026-24191: NVIDIA Display Driver for Windows contains a vulnerability where an attacker could cause a time-of-c NVIDIA Display Driver for Windows contains a vulnerability where an attacker could cause a time-of-check time-of-use issue. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.
nvd
CVE-2025-23309P3HIGHCVSS 8.2vAll driver versions prior to 581.42vAll driver versions prior to 573.76+1 more2025-10-10
CVE-2025-23309 [HIGH] CWE-427 CVE-2025-23309: NVIDIA Display Driver contains a vulnerability where an uncontrolled DLL loading path might lead to NVIDIA Display Driver contains a vulnerability where an uncontrolled DLL loading path might lead to arbitrary denial of service, escalation of privileges, code execution, and data tampering.
nvd
CVE-2025-23280P4HIGHCVSS 7.0vAll driver versions prior to 580.95.05vAll driver versions prior to 570.195.03+1 more2025-10-10
CVE-2025-23280 [HIGH] CWE-416 CVE-2025-23280: NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-f NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
nvd
CVE-2025-23282P4HIGHCVSS 7.0vAll driver versions prior to 580.95.05vAll driver versions prior to 570.195.03+1 more2025-10-10
CVE-2025-23282 [HIGH] CWE-415 CVE-2025-23282: NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a ra NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to escalate privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
nvd
CVE-2026-24196P4HIGHCVSS 7.1vAll driver versions prior to 595.71.05vAll driver versions prior to 580.159.03+1 more2026-05-26
CVE-2026-24196 [HIGH] CWE-125 CVE-2026-24196: NVIDIA Display Driver for Linux contains a vulnerability where a user could cause an out-of-bounds r NVIDIA Display Driver for Linux contains a vulnerability where a user could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to denial of service and information disclosure.
nvd
CVE-2026-24197P4MEDIUMCVSS 6.5vAll driver versions prior to 595.71.05vAll driver versions prior to 580.159.03+1 more2026-05-26
CVE-2026-24197 [MEDIUM] CWE-1188 CVE-2026-24197: NVIDIA Display Driver for Linux contains a vulnerability in the Multi-Instance GPU (MIG) partition m NVIDIA Display Driver for Linux contains a vulnerability in the Multi-Instance GPU (MIG) partition management, where an insecure default initialization of memory subsystem routing resources could lead to data corruption or a hang during partition reconfiguration. A successful exploit of this vulnerability might lead to denial of service.
nvd
CVE-2025-33221P4MEDIUMCVSS 6.0vAll driver versions prior to 595.71.05vAll driver versions prior to 580.159.03+4 more2026-05-26
CVE-2025-33221 [MEDIUM] CWE-20 CVE-2025-33221: NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel driver, where a u NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel driver, where a user could cause an incorrect permission assignment for a critical resource. A successful exploit of this vulnerability might lead to data tampering and denial of service.
nvd
Nvidia Tesla vulnerabilities | cvebase