GPU Display Driver: Kernel mode layer integer overflows allow local privilege escalation
CVSS 7.8CVE-2025-33218NVIDIA / GPU stack+1 more CVEscurated
Impact
A local user can trigger an integer overflow in the display driver kernel mode layer and escalate privileges on the host; the vendor split this integer-overflow class across 2 ids in advisory 5747 with no distinguishing detail between them.
Who can reach it
Any tenant with a container
What to do
Upgrade to the fixed NVIDIA driver from advisory 5747; drain and reboot the node once - one upgrade covers both ids.
Also covers 1 CVE
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
CVE-2025-33219
References
Related entries
- GPU Display Driver: Local privesc (insufficient permission checks)CVE-2026-24190 · GPU Display DriverHigh
- GPU Display Driver: Local privesc (synchronization issue)CVE-2026-24191 · GPU Display DriverHigh
- GPU Display Driver: Local privesc (integer overflow in address calc)CVE-2026-24192 · GPU Display DriverHigh
- GPU Display Driver: Local privesc (buffer overflow in GPU command processing)CVE-2026-24193 · GPU Display DriverHigh
- GPU Display Driver: Access-control bypassCVE-2025-23277 · GPU Display DriverHigh
- GPU Display Driver: Local privesc / data tampering (missing access control)CVE-2023-0181 · GPU Display DriverHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.