Junglewise Threat Intelligence

CVE-2026-24190: NVIDIA Display Driver improper access control in kernel mode layer

CVE-2026-24190 · Severity: high · CVSS 7.8 · Published 2026-05-26

Technologies: Nvidia Display Driver. Vendors: Nvidia.

Executive brief

NVIDIA has identified a security vulnerability in its graphics drivers for Windows and Linux systems. This driver is essential software that allows the operating system to communicate with the computer's graphics hardware. A local user on the system could exploit this flaw to gain unauthorized access to hardware resources, potentially leading to a full system takeover, data theft, or a complete service outage.

Technical details

A vulnerability exists in the kernel mode layer of the NVIDIA Display Driver for Windows and Linux, classified as a missing authorization issue (CWE-862). An attacker with local user access can exploit this flaw to gain improper access to GPU resources. Successful exploitation can lead to a variety of high-impact outcomes, including local privilege escalation (LPE), arbitrary code execution, information disclosure, and denial of service. The vulnerability is triggered via a local attack vector and does not require user interaction. Users should refer to NVIDIA advisory 5821 for specific patched version numbers.

Affected products

  • NVIDIA Display Driver Windows and Linux versions prior to May 2026 updates

Timeline

  • 2026-05-26: disclosed: Initial publication of the CVE record and NVD entry.

References

Related threats