CVE-2026-24197
Description
NVIDIA Display Driver for Linux contains a vulnerability in the Multi-Instance GPU (MIG) partition management, where an insecure default initialization of memory subsystem routing resources could lead to data corruption or a hang during partition reconfiguration. A successful exploit of this vulnerability might lead to denial of service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
NVIDIA Display Driver for Linux on MIG-equipped hardware has an insecure default initialization that can cause data corruption or a hang when reconfiguring GPU partitions, leading to denial of service.
Vulnerability
The vulnerability resides in the Multi-Instance GPU (MIG) partition management code of the NVIDIA Display Driver for Linux. During partition reconfiguration, the driver uses an insecure default initialization for memory subsystem routing resources. Affected versions are not explicitly listed in the available references, but the driver must be installed on a system with MIG-capable hardware. A local attacker with access to reconfigure MIG partitions can trigger the flaw.
Exploitation
The attacker must have local access to the system and the ability to trigger a MIG partition reconfiguration. This requires sufficient privileges to interact with the NVIDIA driver (e.g., root or the nvidia-mig-mgr service). By initiating a partition reconfiguration sequence, the insecure default initialization of memory routing resources is exercised, potentially leading to data corruption or a system hang.
Impact
Successful exploitation leads to denial of service via a system hang or data corruption within the GPU memory space. The CVSS v3 base score is 6.5 (Medium). The impact is confined to availability and integrity of the GPU subsystem; data confidentiality is not directly affected per the description [1].
Mitigation
No official fix version or release date is provided in the available references. NVIDIA has not yet published a security bulletin or updated driver version addressing this specific CVE. Users should monitor NVIDIA's security advisory page for future updates. No workaround is documented in the supplied materials [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.