CVE-2022-34673
Description
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an out-of-bounds array access may lead to denial of service, information disclosure, or data tampering.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
NVIDIA GPU Display Driver for Linux kernel mode layer has an out-of-bounds array access leading to denial of service, information disclosure, or data tampering.
Vulnerability
The vulnerability resides in the kernel mode layer (nvidia.ko) of the NVIDIA GPU Display Driver for Linux. An out-of-bounds array access can be triggered, affecting driver versions prior to the fixed releases. The exact conditions required to reach the vulnerable code path are not detailed in the available references, but the flaw exists in the kernel module. [1]
Exploitation
An attacker would need to have local access to the system and the ability to interact with the NVIDIA driver, likely through standard graphics API calls or by loading a crafted GPU command stream. The out-of-bounds access can be exploited without special privileges beyond normal user access to the GPU device. The specific sequence of steps is not publicly documented. [1]
Impact
Successful exploitation could lead to denial of service (system crash or hang), information disclosure (leakage of kernel memory), or data tampering (corruption of kernel data structures). The impact is limited to the kernel context, potentially allowing an attacker to escalate privileges or cause system instability. [1]
Mitigation
NVIDIA has released fixed driver versions. For Gentoo Linux, users should upgrade to >=x11-drivers/nvidia-drivers-470.182.03:0/470, >=515.105.01:0/515, >=525.105.17:0/525, or >=530.41.03:0/530 depending on their driver branch. No workaround is available. [1]
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: All versions prior to and including 14.2, 13.4, and 11.9, and all versions prior to the November 2022 release
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- security.gentoo.org/glsa/202310-02mitrevendor-advisory
- nvidia.custhelp.com/app/answers/detail/a_id/5415mitre
News mentions
0No linked articles in our index yet.