NVIDIA warns to all users Linux and Windows to upgrade driver now.

                 [FONT=Arial]**NVIDIA GPU Driver Update Addresses Nearly 30 Vulnerabilities**[/FONT]
                 [FONT=Arial]**(November 28, 30, & December 1, 2022)**
                 [/FONT]
                 NVIDIA has released an update for its GPU Display Driver to address  29 vulnerabilities which could be exploited to achieve code execution,  denial of service, escalation of privileges, information disclosure, or  data tampering. The two most serious issues, both of which affect NVIDIA  GPU Display Driver for Windows, are “a vulnerability in the user mode  layer, where an unprivileged regular user can access or modify system  files or other files that are critical to the application … [and] a  vulnerability in the user mode layer, where an unprivileged regular user  can cause an out-of-bounds write.”
                 
                 **Editor's Note**
                
                [Neely](https://www.sans.org/profiles/lee-neely/)]
                The vulnerabilities are on both Linux and Windows systems, so you  need to deploy the update to both platforms. The Linux updates address  weaknesses in the kernel mode layer of the driver which could be  leveraged for DOS, code execution, data tampering or information  disclosure.
                 
                **Read more in:**
                **- [nvidia.custhelp.com](https://nvidia.custhelp.com/app/answers/detail/a_id/5415)**: Security Bulletin: NVIDIA GPU Display Driver - November 2022
                **- [www.securityweek.com](https://www.securityweek.com/nvidia-patches-many-vulnerabilities-windows-linux-display-drivers)**: Nvidia Patches Many Vulnerabilities in Windows, Linux Display Drivers
                **- [www.darkreading.com](https://www.darkreading.com/application-security/nvidia-gpu-driver-bugs-device-takeover)**: Nvidia GPU Driver Bugs Threaten Device Takeover & More
                **- [www.bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/nvidia-releases-gpu-driver-update-to-fix-29-security-flaws/)**: NVIDIA releases GPU driver update to fix 29 security flawsv

This would require user access, local or remotely, correct?

Any website that is compromised can force download a “rust based malware” that can get on any system - linux or windows.

The cure to prevent this has been added to Firefox 107. Google has patched Chrome. Microsoft has yet to patch Edge, Apple has an emergency patch for Safari - they have not said what IOS version get it and which ones not supported will not get the patch.

That is what reported on December 2, 2022.