PatchSiren cyber security CVE debrief
CVE-2026-24197 NVIDIA CVE debrief
A vulnerability in NVIDIA Display Driver for Linux affects Multi-Instance GPU (MIG) partition management. The issue stems from insecure default initialization of memory subsystem routing resources during partition reconfiguration, which could result in data corruption or system hang. Successful exploitation may lead to denial of service. The vulnerability is classified as CWE-1188 (Insecure Default Initialization of Resource). The CVSS 3.1 vector indicates a local attack vector with low attack complexity, low privileges required, no user interaction, and changed scope, resulting in high availability impact.
- Vendor
- NVIDIA
- Product
- GeForce
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-26
- Original CVE updated
- 2026-05-26
- Advisory published
- 2026-05-26
- Advisory updated
- 2026-05-26
Who should care
Organizations running NVIDIA GPUs in Linux environments with MIG enabled, particularly cloud service providers and enterprises using GPU virtualization for AI/ML workloads, containerized applications, or multi-tenant GPU sharing configurations.
Technical summary
The vulnerability exists in the Multi-Instance GPU (MIG) partition management component of NVIDIA Display Driver for Linux. During partition reconfiguration, memory subsystem routing resources are initialized with insecure defaults. This improper initialization (CWE-1188) can lead to data corruption or system hang conditions. The attack requires local access with low privileges and no user interaction. The scope changes from the vulnerable component to other resources, with the primary impact being availability degradation through denial of service. No confidentiality or integrity impacts are indicated in the CVSS scoring.
Defensive priority
medium
Recommended defensive actions
- Review NVIDIA security bulletin for affected driver versions and apply recommended updates
- Audit Linux systems running NVIDIA Display Driver with MIG enabled for exposure
- Monitor partition reconfiguration operations for anomalous behavior or hangs
- Implement least-privilege access controls for GPU management interfaces
- Establish monitoring for unexpected GPU resource initialization failures
Evidence notes
Vulnerability disclosed via NVIDIA PSIRT and published to NVD on 2026-05-26. Official CVE record and NVD entry confirm the vulnerability details. NVIDIA security bulletin provides vendor-specific guidance.
Official resources
-
CVE-2026-24197 CVE record
CVE.org
-
CVE-2026-24197 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
2026-05-26