
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-23278 is an improper array index validation vulnerability in the NVIDIA GPU Display Driver for Windows and Linux. An attacker with local access can issue a call with crafted parameters to trigger improper index validation, potentially leading to data tampering or denial of service. The vulnerability affects the R575 driver branch and was published on August 2, 2025. It carries a CVSS v3.1 base score of 7.1 (High) (Red Hat CVE, ENISA EUVD).
The root cause is classified as CWE-129 (Improper Validation of Array Index), where the driver fails to adequately validate index values supplied via crafted API call parameters before using them to access internal arrays. This local attack vector requires low privileges and no user interaction, meaning any unprivileged local user or process can trigger the flaw by issuing specially crafted driver calls. The improper index can result in out-of-bounds memory access, enabling data corruption or a system crash. A technical write-up on the vulnerability mechanics has been published by ZeroPath (ZeroPath Blog, ENISA EUVD).
Successful exploitation can result in high integrity impact (data tampering) and high availability impact (denial of service/system crash), with no confidentiality impact per the CVSS scoring. The vulnerability affects systems running NVIDIA GPU Display Drivers on both Windows and Linux platforms, particularly the R575 driver branch, meaning a broad range of workstations, servers, and GPU-accelerated systems are at risk. While the attack is limited to local access, it could be leveraged as part of a privilege escalation chain or used to destabilize GPU-dependent workloads (Red Hat CVE, ENISA EUVD).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-23278 as of the time of writing. The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins are available from Nessus and Qualys for vulnerability scanning purposes (Red Hat CVE, Feedly).
nvlddmkm.sys); kernel oops or panic logs on Linux referencing NVIDIA kernel modules (e.g., nvidia.ko)./dev/nvidia* on Linux).NVIDIA addressed this vulnerability in the July 2025 GPU Display Driver security bulletin (answer ID 5670). Users should update to a patched driver version as specified in the NVIDIA security bulletin for the R575 branch. No specific configuration-based workarounds have been published; upgrading to the patched driver is the recommended remediation. System administrators should prioritize patching on multi-user systems where untrusted local users may have access (NVIDIA Security Bulletin, Red Hat CVE).
The vulnerability was covered by Gaming on Linux, which noted NVIDIA's disclosure of multiple GPU driver security issues in July 2025 (Gaming on Linux). Security Online Info reported that NVIDIA patched 14 vulnerabilities in GPU drivers and vGPU software in the same bulletin (Security Online Info). Community reaction on social media (Mastodon/Infosec.exchange) was limited, with the vulnerability noted as part of a broader batch of NVIDIA driver fixes rather than singled out for particular concern.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."