CVE-2025-23279

NameCVE-2025-23279
DescriptionNVIDIA .run Installer for Linux and Solaris contains a vulnerability where an attacker could use a race condition to escalate privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, denial of service, or data tampering.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1109907, 1109908, 1109909, 1109910, 1109911, 1109912, 1109913, 1109914, 1109915, 1109916, 1109917

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
nvidia-graphics-drivers (PTS)bullseye/non-free470.256.02-2vulnerable
bookworm/non-free-firmware535.247.01-1~deb12u1vulnerable
trixie/non-free-firmware550.163.01-2vulnerable
sid/non-free-firmware, forky/non-free-firmware550.163.01-3vulnerable
nvidia-graphics-drivers-legacy-340xx (PTS)sid/non-free340.108-25vulnerable
nvidia-graphics-drivers-legacy-390xx (PTS)bullseye/non-free390.157-1~deb11u1vulnerable
sid/non-free390.157-13vulnerable
nvidia-graphics-drivers-tesla (PTS)bookworm/non-free-firmware525.147.05-15~deb12u1fixed
sid/non-free-firmware525.147.05-16fixed
nvidia-graphics-drivers-tesla-418 (PTS)bullseye/non-free418.226.00-6~deb11u2vulnerable
sid/non-free418.226.00-19vulnerable
nvidia-graphics-drivers-tesla-450 (PTS)bullseye/non-free450.248.02-7~deb11u1fixed
sid/non-free450.248.02-11fixed
nvidia-graphics-drivers-tesla-460 (PTS)bullseye/non-free460.106.00-17~deb11u1fixed
sid/non-free460.106.00-21fixed
nvidia-graphics-drivers-tesla-470 (PTS)bullseye/non-free470.256.02-1~deb11u2vulnerable
bookworm/non-free470.256.02-1~deb12u1vulnerable
sid/non-free470.256.02-7vulnerable
nvidia-graphics-drivers-tesla-535 (PTS)bookworm/non-free-firmware535.216.03-3~deb12u1vulnerable
sid/non-free-firmware, forky/non-free-firmware, trixie/non-free-firmware535.261.03-1fixed
nvidia-graphics-drivers-tesla-550 (PTS)sid/non-free-firmware550.54.15-2vulnerable
nvidia-open-gpu-kernel-modules (PTS)bookworm/contrib535.247.01-1~deb12u1vulnerable
trixie/contrib550.163.01-2vulnerable
sid/contrib, forky/contrib550.163.01-3vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
nvidia-graphics-driverssource(unstable)(unfixed)1109907
nvidia-graphics-drivers-legacy-340xxsource(unstable)(unfixed)1109908
nvidia-graphics-drivers-legacy-390xxsource(unstable)(unfixed)1109909
nvidia-graphics-drivers-teslasource(unstable)525.147.05-61109914
nvidia-graphics-drivers-tesla-418source(unstable)(unfixed)1109910
nvidia-graphics-drivers-tesla-450source(unstable)450.248.02-41109911
nvidia-graphics-drivers-tesla-460source(unstable)460.106.00-31109912
nvidia-graphics-drivers-tesla-470source(unstable)(unfixed)1109913
nvidia-graphics-drivers-tesla-535source(unstable)535.261.03-11109916
nvidia-graphics-drivers-tesla-550source(unstable)(unfixed)1109917
nvidia-open-gpu-kernel-modulessource(unstable)(unfixed)1109915

Notes

[trixie] - nvidia-graphics-drivers <no-dsa> (Non-free not supported)
[bookworm] - nvidia-graphics-drivers <no-dsa> (Non-free not supported)
[bullseye] - nvidia-graphics-drivers-tesla-418 <ignored> (Non-free not supported)
450.248.02-4 turned the package into a metapackage to aid switching to nvidia-graphics-drivers-tesla-470
460.106.00-3 turned the package into a metapackage to aid switching to nvidia-graphics-drivers-tesla-470
[bookworm] - nvidia-graphics-drivers-tesla-470 <no-dsa> (Non-free not supported)
[bullseye] - nvidia-graphics-drivers-tesla-470 <ignored> (Non-free not supported)
525.147.05-6 turned the package into a metapackage to aid switching to nvidia-graphics-drivers
[trixie] - nvidia-open-gpu-kernel-modules <no-dsa> (Contrib not supported)
[bookworm] - nvidia-open-gpu-kernel-modules <no-dsa> (Contrib not supported)
[bookworm] - nvidia-graphics-drivers-tesla-535 <no-dsa> (Non-free not supported)

Search for package or bug name: Reporting problems