CVE-2012-4225

high
Published 2012-11-19 · Modified 2026-04-29
CVSS v3
CVSS v2
7.2
VIR risk
7.2

Description

NVIDIA UNIX graphics driver before 295.71 and before 304.32 allows local users to write to arbitrary physical memory locations and gain privileges by modifying the VGA window using /dev/nvidia0.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-4225

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://nvidia.custhelp.com/app/answers/detail/a_id/3140

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed304.37-1
debian debianbullseyefixed304.37-1
debian debianforkyfixed304.37-1
debian debiansidfixed304.37-1
debian debiantrixiefixed304.37-1

Application impact

VendorProductVersionsFixed
nvidia nvidiaunix_graphic_driver{"endIncluding":"295.71"}
nvidia nvidiaunix_graphic_driver{"endIncluding":"304.32"}

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.