Integer overflow in GeForce driver for Linux - CVE-2023-25516
Published: June 26, 2023
Vulnerability identifier: #VU77706
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-25516
CWE-ID: CWE-190
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to integer overflow. A local user can trigger an integer overflow and gain access to sensitive information or crash the kernel.
Affected software
GeForce driver for Linux
NVIDIA vGPU software (Virtual GPU Manager) Driver
Gentoo Linux
NVIDIA vGPU software (Virtual GPU Manager) Driver
Gentoo Linux
How to mitigate CVE-2023-25516
Install updates from vendor's website.
GeForce driver for Linux - addressed in versions 470.199.02, 525.125.06, 535.54.03
NVIDIA vGPU software (Virtual GPU Manager) Driver - addressed in versions 11.13, 13.8, 15.3
NVIDIA vGPU software (Virtual GPU Manager) Driver - addressed in versions 11.13, 13.8, 15.3