Executive brief
NVIDIA has identified a security vulnerability in its graphics drivers for Windows and Linux systems. This driver is essential software that allows the operating system to communicate with the computer's graphics hardware. A local user on the system could exploit this flaw to gain unauthorized access to hardware resources, potentially leading to a full system takeover, data theft, or a complete service outage.
Technical details
A vulnerability exists in the kernel mode layer of the NVIDIA Display Driver for Windows and Linux, classified as a missing authorization issue (CWE-862). An attacker with local user access can exploit this flaw to gain improper access to GPU resources. Successful exploitation can lead to a variety of high-impact outcomes, including local privilege escalation (LPE), arbitrary code execution, information disclosure, and denial of service. The vulnerability is triggered via a local attack vector and does not require user interaction. Users should refer to NVIDIA advisory 5821 for specific patched version numbers.
Affected products
- NVIDIA Display Driver Windows and Linux versions prior to May 2026 updates
Timeline
- 2026-05-26: disclosed: Initial publication of the CVE record and NVD entry.