VYPR
Medium severity6.5NVD Advisory· Published May 26, 2026· Updated May 26, 2026

CVE-2026-24197

CVE-2026-24197

Description

NVIDIA Display Driver for Linux contains a vulnerability in the Multi-Instance GPU (MIG) partition management, where an insecure default initialization of memory subsystem routing resources could lead to data corruption or a hang during partition reconfiguration. A successful exploit of this vulnerability might lead to denial of service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

NVIDIA Display Driver for Linux on MIG-equipped hardware has an insecure default initialization that can cause data corruption or a hang when reconfiguring GPU partitions, leading to denial of service.

Vulnerability

The vulnerability resides in the Multi-Instance GPU (MIG) partition management code of the NVIDIA Display Driver for Linux. During partition reconfiguration, the driver uses an insecure default initialization for memory subsystem routing resources. Affected versions are not explicitly listed in the available references, but the driver must be installed on a system with MIG-capable hardware. A local attacker with access to reconfigure MIG partitions can trigger the flaw.

Exploitation

The attacker must have local access to the system and the ability to trigger a MIG partition reconfiguration. This requires sufficient privileges to interact with the NVIDIA driver (e.g., root or the nvidia-mig-mgr service). By initiating a partition reconfiguration sequence, the insecure default initialization of memory routing resources is exercised, potentially leading to data corruption or a system hang.

Impact

Successful exploitation leads to denial of service via a system hang or data corruption within the GPU memory space. The CVSS v3 base score is 6.5 (Medium). The impact is confined to availability and integrity of the GPU subsystem; data confidentiality is not directly affected per the description [1].

Mitigation

No official fix version or release date is provided in the available references. NVIDIA has not yet published a security bulletin or updated driver version addressing this specific CVE. Users should monitor NVIDIA's security advisory page for future updates. No workaround is documented in the supplied materials [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.