Integer overflow in GeForce driver for Linux - CVE-2023-25516

 

Integer overflow in GeForce driver for Linux - CVE-2023-25516

Published: June 26, 2023


Vulnerability identifier: #VU77706
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-25516
CWE-ID: CWE-190
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to integer overflow. A local user can trigger an integer overflow and gain access to sensitive information or crash the kernel.


Affected software

GeForce driver for Linux
NVIDIA vGPU software (Virtual GPU Manager) Driver
Gentoo Linux

How to mitigate CVE-2023-25516

Install updates from vendor's website.

GeForce driver for Linux - addressed in versions 470.199.02, 525.125.06, 535.54.03
NVIDIA vGPU software (Virtual GPU Manager) Driver - addressed in versions 11.13, 13.8, 15.3

External References

Related Security Bulletins