CVE-2025-23278

Public on 2025-07-31
Modified on 2025-08-04
Description
NVIDIA Display Driver for Linux and Windows contains a vulnerability where an attacker might cause an improper index validation by issuing a call with crafted parameters. A successful exploit of this vulnerability might lead to data tampering or denial of service.
Severity
Important severity
Important
See what this means
CVSS v3 Base Score
7.1
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2023 cuda-compat 2025-08-04 ALAS2023NVIDIA-2025-142 Fixed
Amazon Linux 2023 cuda-drivers 2025-08-04 ALAS2023NVIDIA-2025-141 Fixed
Amazon Linux 2023 kmod-nvidia-latest-dkms 2025-08-04 ALAS2023NVIDIA-2025-140 Fixed
Amazon Linux 2023 kmod-nvidia-open-dkms 2025-08-04 ALAS2023NVIDIA-2025-139 Fixed
Amazon Linux 2023 libnvidia-nscq-570 2025-08-04 ALAS2023NVIDIA-2025-137 Fixed
Amazon Linux 2023 libnvsdm-570 2025-08-04 ALAS2023NVIDIA-2025-136 Fixed
Amazon Linux 2023 nvidia-driver 2025-08-04 ALAS2023NVIDIA-2025-138 Fixed
Amazon Linux 2023 nvidia-imex-570 2025-08-04 ALAS2023NVIDIA-2025-135 Fixed
Amazon Linux 2023 nvidia-kmod-common 2025-08-04 ALAS2023NVIDIA-2025-134 Fixed
Amazon Linux 2023 nvidia-modprobe 2025-08-04 ALAS2023NVIDIA-2025-133 Fixed
Amazon Linux 2023 nvidia-open 2025-08-04 ALAS2023NVIDIA-2025-132 Fixed
Amazon Linux 2023 nvidia-persistenced 2025-08-04 ALAS2023NVIDIA-2025-131 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
NVD CVSSv3 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H