April 2025 NVIDIA GPU Display Driver Bulletin: Privilege Escalation and vGPU Resource Exploitation
| CVE | Score | Component | Disclosed |
|---|---|---|---|
| CVE-2025-23244 | High | GPU Display Driver — Linux kernel mode | April 24, 2025 |
| CVE-2025-23245 | Medium | vGPU Manager — Virtual GPU Manager plugin | April 24, 2025 |
| CVE-2025-23246 | Medium | vGPU Manager — Virtual GPU Manager plugin | April 24, 2025 |
For executives
NVIDIA's April 2025 GPU display driver security bulletin patched three vulnerabilities spanning the Linux GPU kernel driver and the Virtual GPU Manager. CVE-2025-23244 allows an unprivileged local attacker to escalate permissions on a Linux GPU host — from an ordinary user account to code execution with elevated privileges. The two vGPU vulnerabilities allow a malicious guest virtual machine to affect host resources.
CVE-2025-23244: Privilege escalation in the Linux GPU kernel driver
An unprivileged attacker on a system where the NVIDIA driver is installed can exploit this vulnerability to escalate permissions. Kernel-level access on a GPU host means access to NVIDIA driver internals — including the memory management structures that track which VRAM regions are allocated to which containers or processes. Windows is not affected by CVE-2025-23244.
CVE-2025-23245: vGPU guest accessing global host resources
A guest VM can access global resources on the host that it should not be able to reach. The disclosed consequence is denial of service — the guest can disrupt host operations or affect other guests' availability.
CVE-2025-23246: vGPU guest consuming uncontrolled host resources
A guest can consume resources beyond its allocation without enforcement, causing resource exhaustion and denial of service against the host or other co-located guests.
Patch
Update the GPU Display Driver via the NVIDIA Driver Downloads page. For vGPU software and Cloud Gaming deployments, updates are available through the NVIDIA Licensing Portal.
