CVE-2015-5950

medium
Published 2015-09-30 · Modified 2026-05-06
CVSS v3
CVSS v2
6.9
VIR risk
6.9

Description

The NVIDIA display driver R352 before 353.82 and R340 before 341.81 on Windows; R304 before 304.128, R340 before 340.93, and R352 before 352.41 on Linux; and R352 before 352.46 on GRID vGPU and vSGA allows local users to write to an arbitrary kernel memory location and consequently gain privileges via a crafted ioctl call.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2015-5950

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://nvidia.custhelp.com/app/answers/detail/a_id/3763/~/cve-2015-5950-memory-corruption-due-to-an-unsanitized-pointer-in-the-nvidia

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed340.93-1
debian debianbullseyefixed340.93-1
debian debianforkyfixed340.93-1
debian debiansidfixed340.93-1
debian debiantrixiefixed340.93-1

Application impact

VendorProductVersionsFixed
nvidia nvidiagpu_driver{"endIncluding":"352.30"}
nvidia nvidiadisplay_driver{"endIncluding":"352.09"}
nvidia nvidiadisplay_driver304.108
nvidia nvidiadisplay_driver304.119
nvidia nvidiadisplay_driver304.121
nvidia nvidiadisplay_driver304.123
nvidia nvidiadisplay_driver304.125
nvidia nvidiadisplay_driver352.21
nvidia nvidiadisplay_driver352.30
nvidia nvidiadisplay_driver340.43
nvidia nvidiadisplay_driver340.52
nvidia nvidiadisplay_driver341.44
nvidia nvidiadisplay_driver353.06

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.