Executive brief
NVIDIA has identified a security vulnerability in the kernel drivers for its Windows and Linux display software, which are used to manage graphics hardware performance and output. An attacker with high-level system privileges could exploit this flaw to incorrectly assign permissions to critical system resources. This could lead to data being tampered with or cause the system to crash, resulting in a denial of service for legitimate users.
Technical details
A vulnerability exists in the NVIDIA Display Driver kernel driver for both Windows and Linux platforms. The flaw is categorized as an incorrect permission assignment for a critical resource (CWE-20/CWE-281), allowing a local attacker with high privileges (PR:H) to manipulate resource access. Successful exploitation can lead to data integrity issues (tampering) or a system-wide denial of service (DoS). The attack vector is local, requiring the attacker to already have a foothold on the system. Users are advised to refer to NVIDIA advisory a_id 5821 for specific patched version numbers.
Affected products
- NVIDIA Display Driver Windows and Linux versions prior to May 2026 updates
Timeline
- 2026-05-26: disclosed: Initial public disclosure by NVIDIA
- 2026-05-26: advisory: NVIDIA security bulletin published