Executive brief
NVIDIA has identified a security vulnerability in its graphics drivers for Linux systems. This driver is essential software that allows the operating system to communicate with NVIDIA hardware. If exploited, a local user could gain full control over the system, access sensitive data, or cause the computer to crash, potentially disrupting business operations and compromising system integrity.
Technical details
A use-after-free vulnerability (CWE-416) exists in the NVIDIA Display Driver for Linux. The flaw occurs when the driver continues to use a pointer after it has been freed, leading to memory corruption. An attacker with local access and low-level privileges can exploit this to trigger a crash (DoS), leak sensitive information, or escalate privileges to a higher level, potentially gaining system-level access. The vulnerability is assigned a CVSS score of 8.8, reflecting its high impact on confidentiality, integrity, and availability. Users are advised to refer to NVIDIA's security bulletin for specific driver version updates and patches.
Affected products
- NVIDIA Display Driver for Linux
Timeline
- 2026-05-26: advisory: Initial disclosure by NVIDIA and NVD publication.