Executive brief
A vulnerability in NVIDIA display drivers for Windows and Linux could allow a local user to cause a system-wide denial of service. The driver, which manages how the computer's hardware displays graphics, fails to properly manage internal locks. An attacker can exploit this to freeze or crash the system, disrupting operations and requiring a reboot to restore service.
Technical details
NVIDIA Display Driver for Windows and Linux is vulnerable to improper locking (CWE-667). The flaw allows a local attacker with low privileges to leak held driver locks. Because the vulnerability has a scope impact (S:C), the resulting lock exhaustion or deadlock can affect the stability of the entire operating system. A successful exploit results in a denial of service (DoS) condition. Users are advised to refer to NVIDIA advisory 5821 for specific patched version numbers.
Affected products
- NVIDIA Display Driver Windows and Linux versions
Timeline
- 2026-05-26: disclosed: Initial publication of the CVE record