Junglewise Threat Intelligence

CVE-2026-24195: NVIDIA Display Driver for Linux improper input validation in UVM

CVE-2026-24195 · Severity: high · CVSS 7.1 · Published 2026-05-26

Technologies: Nvidia Display Driver for Linux, Nvidia Display Driver. Vendors: Nvidia.

Executive brief

A vulnerability exists in the NVIDIA Display Driver for Linux within its Unified Memory (UVM) component. This component is responsible for managing memory shared between the system CPU and the NVIDIA GPU. An attacker could exploit this flaw to cause a system crash or freeze, leading to a denial of service that disrupts operations and availability.

Technical details

The NVIDIA Display Driver for Linux is vulnerable to improper input validation (CWE-20) within the Unified Memory (UVM) kernel module. The UVM module handles memory management and synchronization between the CPU and GPU. A local attacker can exploit this vulnerability by providing specially crafted input to the driver, leading to a denial of service (DoS) condition. The CVSS vector indicates a 'Changed' scope (S:C), suggesting the impact may extend from the driver/user space to the broader system stability. Users are advised to consult NVIDIA security bulletin 5821 for specific patched driver versions.

Affected products

  • NVIDIA Display Driver for Linux Refer to NVIDIA advisory 5821 for specific version ranges.

Timeline

  • 2026-05-26: disclosed: Initial publication of the CVE record.
  • 2026-05-26: advisory: NVIDIA published security bulletin 5821.

References

Related threats