Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-23345

Опубликовано: 23 окт. 2025
Источник: redhat
CVSS3: 6.6
EPSS Низкий

Описание

NVIDIA Display Driver for Windows and Linux contains a vulnerability in a video decoder, where an attacker might cause an out-of-bounds read. A successful exploit of this vulnerability might lead to information disclosure or denial of service.

A vulnerability exists in the video-decoder component of the NVIDIA Display Driver for Windows and Linux. A local, low-privileged user may trigger an out-of-bounds read (CWE-125) in the decoder. On successful exploitation this may lead to information disclosure or possibly a denial of service.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux AI (RHEL AI)rhelai1/bootc-aws-nvidia-rhel9Will not fix
Red Hat Enterprise Linux AI (RHEL AI)rhelai1/bootc-azure-nvidia-rhel9Will not fix
Red Hat Enterprise Linux AI (RHEL AI)rhelai1/bootc-gcp-nvidia-rhel9Will not fix
Red Hat Enterprise Linux AI (RHEL AI)rhelai1/instructlab-nvidia-rhel9Will not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2406087nvidia-display-driver: NVIDIA Display Driver out of bound read

EPSS

Процентиль: 11%
0.00037
Низкий

6.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.4
ubuntu
5 месяцев назад

NVIDIA Display Driver for Windows and Linux contains a vulnerability in a video decoder, where an attacker might cause an out-of-bounds read. A successful exploit of this vulnerability might lead to information disclosure or denial of service.

CVSS3: 4.4
nvd
5 месяцев назад

NVIDIA Display Driver for Windows and Linux contains a vulnerability in a video decoder, where an attacker might cause an out-of-bounds read. A successful exploit of this vulnerability might lead to information disclosure or denial of service.

CVSS3: 4.4
debian
5 месяцев назад

NVIDIA Display Driver for Windows and Linux contains a vulnerability i ...

CVSS3: 4.4
github
5 месяцев назад

NVIDIA Display Driver for Windows and Linux contains a vulnerability in a video decoder, where an attacker might cause an out-of-bounds read. A successful exploit of this vulnerability might lead to information disclosure or denial of service.

CVSS3: 4.4
fstec
6 месяцев назад

Уязвимость компонента Video Decoder драйвера программного обеспечения графического процессора NVIDIA GPU Display Driver, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 11%
0.00037
Низкий

6.6 Medium

CVSS3