PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-24190 NVIDIA CVE debrief

NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause improper access to GPU resources. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.

Vendor
NVIDIA
Product
GeForce
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-26
Original CVE updated
2026-06-11
Advisory published
2026-05-26
Advisory updated
2026-06-11

Who should care

Organizations running NVIDIA Display Drivers on Windows or Linux workstations and servers, particularly those with multi-user environments or where local access cannot be fully restricted. System administrators responsible for GPU-accelerated computing environments, VDI deployments, and development workstations using NVIDIA graphics hardware.

Technical summary

This vulnerability exists in the kernel mode layer of NVIDIA Display Driver for both Windows and Linux platforms. The flaw allows a user to cause improper access to GPU resources. The CVSS 3.1 score of 7.8 (HIGH) reflects local attack vector with low attack complexity, low privileges required, and high impacts across confidentiality, integrity, and availability. The identified weakness is CWE-862 (Missing Authorization). Successful exploitation could result in multiple severe outcomes including denial of service, privilege escalation, information disclosure, data tampering, and code execution. The kernel-level nature of this vulnerability makes it particularly dangerous as it bypasses user-mode security boundaries.

Defensive priority

HIGH

Recommended defensive actions

  • Apply NVIDIA security updates per vendor guidance when available
  • Restrict local access to systems running affected NVIDIA Display Driver versions
  • Monitor for anomalous GPU resource utilization or kernel-level activity
  • Review NVIDIA security bulletin for affected driver versions and patch timeline
  • Implement principle of least privilege for user accounts with local system access

Evidence notes

CVE published 2026-05-26T18:16:37.847Z; modified 2026-05-26T19:08:15.080Z. CVSS 3.1 vector: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. CWE-862 (Missing Authorization) identified as primary weakness. Source references include NVIDIA security bulletin.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-24190 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-24190

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-24190 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-24190

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.