VYPR
High severity7.1NVD Advisory· Published May 26, 2026· Updated May 26, 2026

CVE-2026-24195

CVE-2026-24195

Description

NVIDIA Display Driver for Linux contains a vulnerability in UVM, where a user could cause improper input validation. A successful exploit of this vulnerability might lead to denial of service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

NVIDIA Linux Display Driver UVM vulnerability enables improper input validation, leading to denial of service (DoS).

Vulnerability

The NVIDIA Display Driver for Linux contains a vulnerability in the UVM (Unified Virtual Memory) component [1]. Improper input validation occurs when a user interacts with the driver, allowing an attacker to trigger a denial of service condition. The vulnerability is present in the Linux driver versions prior to the fix, and the exact code path depends on the specific UVM operations invoked by the user. The CVSS v3.1 base score is 7.1 (High), indicating significant availability impact [1].

Exploitation

An attacker needs local user access to the system to exploit this vulnerability [1]. No special authentication or write access is required; the attacker only needs to cause improper input validation through a user operation (e.g., invoking a UVM function with crafted parameters). The attack does not require a race window or precise timing; it is a straightforward input validation flaw that leads to driver instability and denial of service.

Impact

A successful exploit causes denial of service for the affected system [1]. The availability impact is complete (C: None, I: None, A: High), meaning the driver crash or hang renders the system unusable until recovery. No confidentiality or integrity compromise occurs; the vulnerability solely disrupts operations.

Mitigation

NVIDIA has released a driver update to address this vulnerability [1]. Users should upgrade to the latest patched version of the NVIDIA Display Driver for Linux. No workarounds are documented; the fix is the recommended mitigation. The vulnerability is not listed in any known KEV catalog as of the publication date.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.