PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-24197 NVIDIA CVE debrief

A vulnerability in NVIDIA Display Driver for Linux affects Multi-Instance GPU (MIG) partition management. The issue stems from insecure default initialization of memory subsystem routing resources during partition reconfiguration, which could result in data corruption or system hang. Successful exploitation may lead to denial of service. The vulnerability is classified as CWE-1188 (Insecure Default Initialization of Resource). The CVSS 3.1 vector indicates a local attack vector with low attack complexity, low privileges required, no user interaction, and changed scope, resulting in high availability impact.

Vendor
NVIDIA
Product
GeForce
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-26
Original CVE updated
2026-06-11
Advisory published
2026-05-26
Advisory updated
2026-06-11

Who should care

Organizations running NVIDIA GPUs in Linux environments with MIG enabled, particularly cloud service providers and enterprises using GPU virtualization for AI/ML workloads, containerized applications, or multi-tenant GPU sharing configurations.

Technical summary

The vulnerability exists in the Multi-Instance GPU (MIG) partition management component of NVIDIA Display Driver for Linux. During partition reconfiguration, memory subsystem routing resources are initialized with insecure defaults. This improper initialization (CWE-1188) can lead to data corruption or system hang conditions. The attack requires local access with low privileges and no user interaction. The scope changes from the vulnerable component to other resources, with the primary impact being availability degradation through denial of service. No confidentiality or integrity impacts are indicated in the CVSS scoring.

Defensive priority

medium

Recommended defensive actions

  • Review NVIDIA security bulletin for affected driver versions and apply recommended updates
  • Audit Linux systems running NVIDIA Display Driver with MIG enabled for exposure
  • Monitor partition reconfiguration operations for anomalous behavior or hangs
  • Implement least-privilege access controls for GPU management interfaces
  • Establish monitoring for unexpected GPU resource initialization failures

Evidence notes

Vulnerability disclosed via NVIDIA PSIRT and published to NVD on 2026-05-26. Official CVE record and NVD entry confirm the vulnerability details. NVIDIA security bulletin provides vendor-specific guidance.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-24197 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-24197

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-24197 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-24197

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.