Executive brief
NVIDIA has identified a security vulnerability in its graphics drivers for Linux systems. This driver is essential for managing how the computer's hardware displays images and processes data. If exploited, a local user could bypass security restrictions to gain full control over the system, access sensitive data, or cause the computer to crash, potentially disrupting business operations and compromising system integrity.
Technical details
A vulnerability exists in the NVIDIA Display Driver for Linux within a kernel mode layer handler, classified as improper preservation of permissions (CWE-281). The flaw allows a local attacker with low privileges to exploit improper permission handling to gain elevated access. Successful exploitation can lead to arbitrary code execution in kernel mode, full escalation of privileges, unauthorized information disclosure, or a denial of service (DoS) condition. The attack requires local system access but no user interaction. Users are advised to refer to NVIDIA advisory 5821 for specific patched driver versions.
Affected products
- NVIDIA Display Driver for Linux
Timeline
- 2026-05-26: disclosed: Initial publication of the CVE record.