CVE-2025-23280 is a use-after-free vulnerability in the NVIDIA Display Driver for Linux. According to the provided content, the flaw stems from improper memory management in the Linux driver, where a memory object can be freed while a dangling reference is retained and later dereferenced. Exploitation involves triggering a code path that uses the stale pointer after free and, by winning a race condition, reallocating the freed region with attacker-controlled data. The issue affects NVIDIA Linux display driver branches R580 before 580.95.05, R570 before 570.195.03, and R535 before 535.274.02. Successful exploitation may result in code execution in kernel context, privilege escalation, data tampering, denial of service, and information disclosure.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A use-after-free vulnerability in NVIDIA Linux drivers mentioned as another vulnerability disclosed in NVIDIA's October 2025 bulletin.
A use-after-free vulnerability in the NVIDIA Display Driver for Linux that can allow local attackers to achieve kernel-context code execution, privilege escalation, data tampering, denial of service, or information disclosure.
A related NVIDIA vulnerability identified as a use-after-free issue, mentioned as part of NVIDIA's 2025 security bulletins.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.