PatchSiren cyber security CVE debrief
CVE-2026-24195 NVIDIA CVE debrief
A vulnerability in NVIDIA Display Driver for Linux's Unified Virtual Memory (UVM) component allows improper input validation, potentially leading to denial of service. The CVSS 3.1 score of 7.1 (HIGH) reflects local attack vector with low attack complexity, no privileges required, no user interaction, and changed scope, with high availability impact. The vulnerability is classified under CWE-20 (Improper Input Validation). As of publication, the CVE status is 'Undergoing Analysis' per NVD. No known exploitation in ransomware campaigns has been reported, and the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog.
- Vendor
- NVIDIA
- Product
- Guest driver
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-26
- Original CVE updated
- 2026-06-11
- Advisory published
- 2026-05-26
- Advisory updated
- 2026-06-11
Who should care
Organizations running NVIDIA Display Driver for Linux with UVM enabled, particularly multi-user Linux environments where local unprivileged access is possible. System administrators responsible for GPU driver maintenance and security teams monitoring for local privilege escalation or denial-of-service vectors in graphics driver stacks.
Technical summary
The vulnerability exists in the Unified Virtual Memory (UVM) component of NVIDIA Display Driver for Linux. Improper input validation allows a local, unprivileged user to trigger conditions that may result in denial of service. The attack requires local access but no user interaction or elevated privileges. The changed scope (S:C) in the CVSS vector indicates the vulnerable component impacts resources beyond its security scope.
Defensive priority
HIGH
Recommended defensive actions
- Monitor NVIDIA security bulletins for driver updates addressing CVE-2026-24195
- Apply updated NVIDIA Display Driver for Linux versions when available from NVIDIA
- Review systems running NVIDIA Display Driver for Linux for UVM module usage
- Implement principle of least privilege to limit local attack surface
- Monitor for anomalous UVM-related system behavior or crashes indicating potential exploitation attempts
Evidence notes
Vulnerability description and CVSS vector sourced from NVD record. Vendor attribution to NVIDIA derived from source references including [email protected] contact and NVIDIA customer help domain. CWE-20 classification confirmed via NVD weaknesses field. CVE status 'Undergoing Analysis' indicates ongoing evaluation.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-24195 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-24195
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-24195 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-24195
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://nvidia.custhelp.com/app/answers/detail/a_id/5821
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.