Conversation

From kernel oops to kernel exploit: How two little bugs (CVE-2025-23330, CVE-2025-23280) in open GPU driver can lead to full system compromise.

Full technical breakdown inside, exploitation technique included!

https://blog.quarkslab.com/nvidia_gpu_kernel_vmalloc_exploit.html

1
5
0
@quarkslab Well. Actually, three bugs. "The bugs can be triggered by an attacker controlling a local unprivileged process." You have to get shell access, first. And maybe more, because we don't normally let "nobody" user talk to gpu and v4l2...?
0
0
0