CVE-2025-23277
Public on 2025-07-31
        Modified on 2025-07-31
        
      Description
            
              NVIDIA Display Driver for Linux and Windows contains a vulnerability in the kernel mode driver, where an attacker could access memory outside bounds permitted under normal use cases. A successful exploit of this vulnerability might lead to denial of service, data tampering, or information disclosure.
            
          Severity
          
          See what this means
        CVSS v3 Base Score
          
          See breakdown
        Affected Packages
| Platform | Package | Release Date | Advisory | Status | 
|---|---|---|---|---|
| Amazon Linux 2023 | cuda-compat | 2025-08-04 | ALAS2023NVIDIA-2025-142 | Fixed | 
| Amazon Linux 2023 | cuda-drivers | 2025-08-04 | ALAS2023NVIDIA-2025-141 | Fixed | 
| Amazon Linux 2023 | kmod-nvidia-latest-dkms | 2025-08-04 | ALAS2023NVIDIA-2025-140 | Fixed | 
| Amazon Linux 2023 | kmod-nvidia-open-dkms | 2025-08-04 | ALAS2023NVIDIA-2025-139 | Fixed | 
| Amazon Linux 2023 | libnvidia-nscq-570 | 2025-08-04 | ALAS2023NVIDIA-2025-137 | Fixed | 
| Amazon Linux 2023 | libnvsdm-570 | 2025-08-04 | ALAS2023NVIDIA-2025-136 | Fixed | 
| Amazon Linux 2023 | nvidia-driver | 2025-08-04 | ALAS2023NVIDIA-2025-138 | Fixed | 
| Amazon Linux 2023 | nvidia-imex-570 | 2025-08-04 | ALAS2023NVIDIA-2025-135 | Fixed | 
| Amazon Linux 2023 | nvidia-kmod-common | 2025-08-04 | ALAS2023NVIDIA-2025-134 | Fixed | 
| Amazon Linux 2023 | nvidia-modprobe | 2025-08-04 | ALAS2023NVIDIA-2025-133 | Fixed | 
| Amazon Linux 2023 | nvidia-open | 2025-08-04 | ALAS2023NVIDIA-2025-132 | Fixed | 
| Amazon Linux 2023 | nvidia-persistenced | 2025-08-04 | ALAS2023NVIDIA-2025-131 | Fixed | 
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H | 
| NVD | CVSSv3 | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |