VYPR
Unrated severityNVD Advisory· Published Dec 30, 2022· Updated Apr 10, 2025

CVE-2022-42256

CVE-2022-42256

Description

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer (nvidia.ko), where an integer overflow in index validation may lead to denial of service, information disclosure, or data tampering.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Integer overflow in NVDIA GPU Display Driver's kernel mode layer for Linux allows denial of service, information disclosure, or data tampering.

Vulnerability

An integer overflow vulnerability exists in the kernel mode layer (nvidia.ko) of the NVIDIA GPU Display Driver for Linux. The flaw occurs during index validation, potentially leading to memory corruption. Affected versions include driver branches 470, 515, 525, and 530 prior to the fixed releases listed in the Gentoo advisory [1].

Exploitation

An attacker with local user access to a system running an affected NVIDIA driver can trigger the integer overflow by interacting with the driver's kernel interface, though the exact sequence of steps required is not detailed in public references. No user interaction beyond normal system usage is specified; the exploitation likely involves passing crafted inputs to the driver's IOCTL handlers [1].

Impact

Successful exploitation may cause denial of service (system crash), information disclosure (kernel memory leak), or data tampering (corruption of kernel structures). The scope is limited to confidentiality, integrity, and availability impacts on the local system, with an attack vector requiring local access as per the CVSS specification [1].

Mitigation

The vulnerabilities are addressed in driver versions 470.182.03, 515.105.01, 525.105.17, and 530.41.03 for the respective branches. Gentoo users can upgrade by running the emerge commands provided in the advisory [1]. No workaround is available; upgrading to the fixed drivers is the only mitigation.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • NVIDIA/vGPU software (guest driver) - Linux, vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (guest driver), NVIDIA Cloud Gaming (Virtual GPU Manager)v5
    Range: All versions prior to and including 14.2, 13.4, and 11.9, and all versions prior to the November 2022 release

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.