Heap Buffer Overflow in NVIDIA Display Driver for Linux
CVE-2026-24192

7.8HIGH

Key Information:

Vendor

Nvidia

Vendor
CVE Published:
26 May 2026

What is CVE-2026-24192?

The NVIDIA Display Driver for Linux has a critical vulnerability that arises from an improper conversion between numeric types, resulting in a heap buffer overflow. This flaw could potentially allow an attacker to exploit the system, leading to various malicious outcomes including denial of service, privilege escalation, disclosure of sensitive information, data tampering, and remote code execution. Organizations using affected versions should take immediate action to mitigate risks associated with this vulnerability.

Affected Version(s)

GeForce Linux(R535) All driver versions prior to 535.309.01

GeForce Linux(R580) All driver versions prior to 580.159.03

GeForce Linux(R595) All driver versions prior to 595.71.05

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.