Executive brief
NVIDIA GPU drivers for Linux systems contain a security flaw that could allow a highly privileged user to access sensitive system memory. An attacker who already has significant control over a system could exploit this to cause a system crash, tamper with data, or steal confidential information. This primarily impacts the stability and data privacy of Linux-based workstations and servers using NVIDIA hardware.
Technical details
A race condition vulnerability exists in the NVIDIA GPU Display Driver for Linux. The flaw is categorized under CWE-200 (Exposure of Sensitive Information) and allows a local attacker with high privileges (PR:H) to trigger a race condition to leak sensitive memory. Successful exploitation can result in limited information disclosure, data tampering, or a denial-of-service (DoS) condition. The attack vector is local and does not require user interaction. Users are advised to refer to NVIDIA advisory a_id/5821 for specific patched driver versions.
Affected products
- NVIDIA GPU Display Driver for Linux
Timeline
- 2026-05-26: disclosed: Initial publication of the CVE record.
- 2026-05-26: advisory: NVIDIA released security advisory a_id/5821.