CVE-2026-24197
Analyzed
Analyzed - Analysis Complete
NVIDIA Linux Display Driver MIG Partition Memory Corruption
Publication date: 2026-05-26
Last updated on: 2026-06-11
Assigner: NVIDIA Corporation
Description
Description
NVIDIA Display Driver for Linux contains a vulnerability in the Multi-Instance GPU (MIG) partition management, where an insecure default initialization of memory subsystem routing resources could lead to data corruption or a hang during partition reconfiguration. A successful exploit of this vulnerability might lead to denial of service.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| nvidia | gpu_display_driver | From 595 (inc) to 595.71.05 (exc) |
| nvidia | gpu_display_driver | From 535 (inc) to 535.309.01 (exc) |
| nvidia | gpu_display_driver | From 580 (inc) to 580.159.03 (exc) |
| nvidia | gpu_display_driver | From 535 (inc) to 539.72 (exc) |
| nvidia | gpu_display_driver | From 580 (inc) to 582.53 (exc) |
| nvidia | gpu_display_driver | From 595 (inc) to 595.36 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1188 | The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure. |