Executive brief
NVIDIA has identified a security vulnerability in its graphics drivers for Linux systems. This driver is essential software that allows the operating system to communicate with NVIDIA graphics hardware. If exploited, a local user could cause the system to crash or potentially gain unauthorized access to sensitive information stored in the system's memory.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the NVIDIA Display Driver for Linux. The flaw occurs when the driver reads data past the end of the intended buffer. A local attacker with low privileges can exploit this vulnerability without any user interaction. Successful exploitation can result in a denial of service (system crash) or the disclosure of sensitive information from kernel or video memory. The vulnerability is tracked as CVE-2026-24196 and has a CVSS v3.1 base score of 7.1.
Affected products
- NVIDIA Display Driver for Linux
Timeline
- 2026-05-26: disclosed
- 2026-05-26: advisory