Category: NVIDIA

  • NVIDIA security vulnerability (CVE-2025-23352)

    CVE-2025-23352 is a vulnerability identified in NVIDIA’s vGPU software, specifically in the Virtual GPU Manager, where a malicious guest could cause uninitialized pointer access. If exploited successfully, it can lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. Affected versions include all releases prior to and including version 19.1,

    Continue Reading

  • NVIDIA security vulnerability (CVE-2025-23359)

    CVE-2025-23359 is a vulnerability identified in NVIDIA Container Toolkit and GPU Operator for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where a crafted container image could gain access to the host file system. If exploited successfully, it can lead to code execution, denial of service, escalation of privileges, information disclosure,

    Continue Reading

  • NVIDIA security vulnerability (CVE-2024-0128)

    CVE-2024-0128 is a vulnerability identified in NVIDIA’s vGPU software, specifically in the Virtual GPU Manager. This flaw allows a user operating within a guest OS to access global resources improperly. If exploited successfully, it can lead to information disclosure, data tampering, and privilege escalation. Affected versions include all releases prior to version 17.4 and 16.8

    Continue Reading

  • NVIDIA security vulnerability (CVE-2024-0117)

    CVE-2024-0117 is a high-severity vulnerability in NVIDIA GPU Display Driver for Windows. It exists in the user mode layer, where an unprivileged user can trigger an out-of-bounds read. Exploiting this vulnerability may lead to code execution, denial of service, privilege escalation, information disclosure, and data tampering. NVIDIA has assigned it a CVSS 3.1 base score

    Continue Reading

  • NVIDIA security vulnerability (CVE-2024-0127)

    CVE-2024-0127 is a high-severity vulnerability affecting NVIDIA’s vGPU software, specifically in the GPU kernel driver of the vGPU Manager. It affects all supported hypervisors, allowing a user on the guest OS to exploit improper input validation, potentially compromising the guest OS kernel. A successful exploit of this vulnerability might lead to code execution, escalation of

    Continue Reading

  • NVIDIA security vulnerability (CVE-2024-0126)

    CVE-2024-0126 is a high-severity vulnerability affecting NVIDIA GPU Display Drivers for Windows and Linux. It stems from improper input validation (CWE-20) and could allow a privileged attacker to escalate permissions. Exploiting this vulnerability might lead to various outcomes, including arbitrary code execution, denial of service, escalation of privileges, information disclosure, and data tampering. Affected versions

    Continue Reading

  • NVIDIA security vulnerability (CVE-2024-0132)

    CVE-2024-0132 is a critical vulnerability in NVIDIA Container Toolkit (versions 1.16.1 and earlier) and NVIDIA GPU Operator (versions 24.6.1 and earlier). It is classified as a Time-of-Check Time-of-Use (TOCTOU) issue, which could allow an attacker to exploit a flaw in how the container runtime accesses resources, potentially gaining access to the host file system through

    Continue Reading