CVE-2025-33220High
ANC
ANC
Anchore Vulnerability Database overrides
Supplementary feed layered on top of upstream sources. Anchore maintainers publish override records to suppress known false positives and fill CPE/PURL gaps that would otherwise cause Grype and similar scanners to mis-report a system.
Region
US
Updates
6 ч
License
Apache-2.0
Curated corrections to the Anchore/Grype vulnerability database: false-positive suppressions, missing CPE mappings and distro-specific backport fixes.
https://github.com/anchore/grype-db →Share link
Anyone with the link can open this vulnerability.
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause heap memory access after the …
CVSS
7.8
High
EPSS
0.00
p8
Published
2025-01-01
Updated
2025-01-01
Description
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause heap memory access after the memory is freed. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, or information disclosure.
Tags · CWE
LPE
CWE-416
CWE-416VariantStable
Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
https://cwe.mitre.org/data/definitions/416.html →Open in CWE collection →Affected products
Nvidia-graphics-drivers-340Nvidia-graphics-drivers-390Nvidia-graphics-drivers-418-serverNvidia-graphics-drivers-430Nvidia-graphics-drivers-435Nvidia-graphics-drivers-440Nvidia-graphics-drivers-440-serverNvidia-graphics-drivers-450Nvidia-graphics-drivers-450-serverNvidia-graphics-drivers-455Nvidia-graphics-drivers-460Nvidia-graphics-drivers-470Nvidia-graphics-drivers-470Nvidia-graphics-drivers-470-serverNvidia-graphics-drivers-470-serverNvidia-graphics-drivers-510
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Timeline
2025-01-01
Published
2025-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.002 · p8
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
| Product | Vendor | Status |
|---|---|---|
| Tracked | ||
| Tracked | ||
| Tracked | ||
| Tracked | ||
| nvidia-graphics-drivers-340 | Tracked | |
| nvidia-graphics-drivers-390 | Tracked | |
| nvidia-graphics-drivers-418-server | Tracked | |
| nvidia-graphics-drivers-430 | Tracked | |
| nvidia-graphics-drivers-435 | Tracked | |
| nvidia-graphics-drivers-440 | Tracked | |
| nvidia-graphics-drivers-440-server | Tracked | |
| nvidia-graphics-drivers-450 | Tracked | |
| nvidia-graphics-drivers-450-server | Tracked | |
| nvidia-graphics-drivers-455 | Tracked | |
| nvidia-graphics-drivers-460 | Tracked | |
| nvidia-graphics-drivers-470 | Tracked | |
| nvidia-graphics-drivers-470 | Tracked | |
| nvidia-graphics-drivers-470-server | Tracked | |
| nvidia-graphics-drivers-470-server | Tracked | |
| nvidia-graphics-drivers-510 | Tracked |
Showing first 20 of 67
Source databases
ANC
ANC
Anchore Vulnerability Database overrides
Supplementary feed layered on top of upstream sources. Anchore maintainers publish override records to suppress known false positives and fill CPE/PURL gaps that would otherwise cause Grype and similar scanners to mis-report a system.
Region
US
Updates
6 ч
License
Apache-2.0
Curated corrections to the Anchore/Grype vulnerability database: false-positive suppressions, missing CPE mappings and distro-specific backport fixes.
https://github.com/anchore/grype-db →UBU
UBU
Ubuntu Security Notices (USN)
USNs are authoritative for Ubuntu systems. The CVE Tracker links each vulnerability to its per-release status (needed, released, not-affected) and to the exact Launchpad bug where the fix is integrated.
Region
Intl.
Updates
1 ч
License
CC BY-SA 3.0
Security notices for Ubuntu LTS and interim releases, covering main, universe and (via Pro) ESM-extended packages.
https://ubuntu.com/security/notices →External references
https://nvd.nist.gov/vuln/detail/CVE-2025-33220@https://nvidia.custhelp.com/app/answers/detail/a_id/5747@https://www.cve.org/CVERecord?id=CVE-2025-33220https://www.cve.org/CVERecord?id=CVE-2025-33220@https://nvd.nist.gov/vuln/detail/CVE-2025-33220@https://nvidia.custhelp.com/app/answers/detail/a_id/5747@https://www.cve.org/CVERecord?id=CVE-2025-33220