CVE-2018-6260 is a vulnerability in NVIDIA graphics drivers that allows a local user to potentially access application data processed on the GPU via side-channel exposure through GPU performance counters. This medium-severity vulnerability (CVSS 5.5) requires local user access, meaning it is not a remote or network attack. While it could lead to high confidentiality impact, there is no known active exploitation, public exploit code, or significant community discussion, and it is not listed on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:nvidia:gpu_driver:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.