Executive brief
A vulnerability exists in the NVIDIA Linux display driver, which is software used to manage graphics hardware performance and output. A local user with basic access to the system could trigger a race condition that causes the system to crash or become unresponsive. This results in a denial of service, potentially disrupting operations or causing data loss for active sessions on the affected machine.
Technical details
A race condition vulnerability (CWE-362) exists within an NVIDIA Linux kernel module due to improper synchronization of shared resources. An attacker with local user privileges can exploit this by reordering compiler or processor memory instructions to trigger inconsistent states. The attack complexity is high as it requires precise timing or specific execution conditions to successfully trigger the race. If successfully exploited, the vulnerability results in a denial of service (DoS) by crashing the kernel or the display driver.
Affected products
- NVIDIA Display Driver for Linux
Timeline
- 2026-05-26: disclosed
- 2026-05-26: advisory