• Hey Guest. Check out your NeoGAF Wrapped 2025 results here!

[DF] PSA - Upgrade Your Nvidia Graphics Drivers To Avoid a "High-Severity" Vulnerability

Topher

Identifies as young
Nvidia has released one of its rare security bulletins over the last 24 hours, disclosing 15 security vulnerabilities that affect its Windows and Linux graphics drivers. Nine are marked as "high-severity", as they could allow attackers to bork* your PC, gain administrative access, exfiltrate personal data and/or execute arbitrary code. All the bad stuff, basically.

For GeForce graphics card owners, it's therefore recommended to update your drivers to the latest available version, with all versions prior to 596.36 (for modern GeForce GPUs) or 482.53 (for GTX 10-series and earlier GPUs) vulnerable to some or all of these exploits.

If you have the Nvidia app installed on Windows and update your drivers when prompted, it's likely that you're already on the latest 596.49 update released a week ago, but do check to make sure.

For Linux users, your target version is 590.48.01 and you can use the console command nvidia-smi (or the GUI alternative nvidia-settings) to check your current installed driver version. Using your OS package manager to install the latest available updates is normally the best way to proceed on most distributions.

psa-upgrade-your-nvidia-graphics-drivers-to-avoid-a-high-severity-vulnerability-2.970x.jpg


The Nvidia disclosure page includes all of the grisly technical details if you'd like to learn more, including information of interest to owners of non-gaming GPUs like Quadro, NVS and Tesla.


 
300px-No%2C_I_don%27t_think_I_will.jpg


im still on windows 10 so im already yolo'ing. but this sounds serious. fuck. i hate installing new nvidia drivers. you never know which one will downgrade performance randomly in games.
 
Why the heck didn't they use AI to find those quicker? (#LowBlow)
They are, hence this warning.
I'm seeing it all over the IT industry, until last month security was just an afterthought where I work at, now every CI/CD pipeline gets blocked every single week from some new vulnerability that shows up.
Most big companies have begun to understand that they cannot fuck around anymore with AI being so capable of finding holes in the security of their systems.
 
Last edited:
They are, hence this warning.
I'm seeing it all over the IT industry, until last month security was just an afterthought where I work at, now every CI/CD pipeline gets blocked every single week from some new vulnerability that shows up.
Most big companies have begun to understand that they cannot fuck around anymore with AI being so capable of finding holes in the security of their systems.
I dont quite agree with that (im a senior backend dev, and i get you are saying), Nvidia, evne for advertising, should be the FIRST to show these kinds of AI applications.

And Linus (you know, Linux) is tired of having the same 500 reports of the same hypothetical fail, so even this AI practical usage is not that well used...
 
What do you mean? As in only workstations have sensitive stuff on it or will be targeted?
That and vectors with which an attacker can get access to the computer to begin with - necessary step for these types of vulnerabilities to even matter. In a company, there are multiple ways for an attacker to gain access to a computer, through one of multiple employees, direct physical access, or even being a employee themselves. As such, the computer itself being secure is important. But for a home computer only you use? As long as you're not downloading weird stuff from the net or clicking suspicious links, it is very unlikely.
 
Last edited:
Nice drivers. It literally cut my framerates in half on 5080 lmao. Never installing latest drivers ever again.

I'm not actually joking tho



96.49 Testing

Something's not right, a mixed bag.

To rule out a Windows update issue 596.49 was also tested on Windows 11 KB5083769 (26200.8246 / 26100.8246).

Despite being a very minor branch update that targeted a DLSS frame generation with Vsync issue there are concerning regressions in general performance metrics and perceived stutter in many games when compared to r595 branch drivers 596.36, 595.79 and 595.76. Ironically framepacing is noticeably improved with 596.49 in games that manifested issues when using DLSS frame generation and Vsync with older r595 branch (595.xx/596.xx) drivers.

So take your posion, security updates or worse performance.
 
Last edited:
. But for a home computer only you use? As long as you're not downloading weird stuff from the net or clicking suspicious links, it is very unlikely.
yeah if you don't get malware through some download or phished into clicking something you're safe but this applies to a workstation too I'd imagine.
 
yeah if you don't get malware through some download or phished into clicking something you're safe but this applies to a workstation too I'd imagine.
Difference is: employees are braindead by default, and there are a lot of them
 
Last edited:
Top Bottom