{"id":"ECHO-8752-7f5c-2930","summary":"CVE-2025-33219 is an integer overflow in the NVIDIA kernel module. Echo ships only\nuserspace compatibility libraries (cuda-compat) via the cuda-13.1 package, not the\nkernel module. The vulnerable code path does not exist in the packages Echo distributes.\nAdditionally, the installed version (590.48.01) is already at the fix threshold per\nNVIDIA Security Bulletin 5747.\nhttps://nvidia.custhelp.com/app/answers/detail/a_id/5747\nhttps://security-tracker.debian.org/tracker/CVE-2025-33219\n","modified":"2026-09-15T03:33:39.491975172Z","published":"2026-01-31T02:00:41.426776Z","withdrawn":"2026-02-12T08:30:03.566Z","upstream":["CVE-2025-33219"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2025-33219"}],"affected":[{"package":{"name":"nvidia-graphics-drivers","ecosystem":"Echo","purl":"pkg:deb/echo/nvidia-graphics-drivers"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"590.48.01-0ubuntu1+e1"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-8752-7f5c-2930.json"}}],"schema_version":"1.9.0"}