Skip to main content

April 2025 NVIDIA GPU Display Driver Bulletin: Privilege Escalation and vGPU Resource Exploitation

CVEScoreComponentDisclosed
CVE-2025-23244HighGPU Display Driver — Linux kernel modeApril 24, 2025
CVE-2025-23245MediumvGPU Manager — Virtual GPU Manager pluginApril 24, 2025
CVE-2025-23246MediumvGPU Manager — Virtual GPU Manager pluginApril 24, 2025

For executives

NVIDIA's April 2025 GPU display driver security bulletin patched three vulnerabilities spanning the Linux GPU kernel driver and the Virtual GPU Manager. CVE-2025-23244 allows an unprivileged local attacker to escalate permissions on a Linux GPU host — from an ordinary user account to code execution with elevated privileges. The two vGPU vulnerabilities allow a malicious guest virtual machine to affect host resources.

CVE-2025-23244: Privilege escalation in the Linux GPU kernel driver

An unprivileged attacker on a system where the NVIDIA driver is installed can exploit this vulnerability to escalate permissions. Kernel-level access on a GPU host means access to NVIDIA driver internals — including the memory management structures that track which VRAM regions are allocated to which containers or processes. Windows is not affected by CVE-2025-23244.

CVE-2025-23245: vGPU guest accessing global host resources

A guest VM can access global resources on the host that it should not be able to reach. The disclosed consequence is denial of service — the guest can disrupt host operations or affect other guests' availability.

CVE-2025-23246: vGPU guest consuming uncontrolled host resources

A guest can consume resources beyond its allocation without enforcement, causing resource exhaustion and denial of service against the host or other co-located guests.

Patch

Update the GPU Display Driver via the NVIDIA Driver Downloads page. For vGPU software and Cloud Gaming deployments, updates are available through the NVIDIA Licensing Portal.