Description
NVIDIA Display Driver for Linux contains a vulnerability in the Multi-Instance GPU (MIG) partition management, where an insecure default initialization of memory subsystem routing resources could lead to data corruption or a hang during partition reconfiguration. A successful exploit of this vulnerability might lead to denial of service.
Published: 2026-05-26
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in NVIDIA’s Linux display driver’s Multi‑Instance GPU (MIG) partition management subsystem. During initialization, the driver fails to secure memory‑routing resources, which can result in data corruption or a system hang when a partition is reconfigured. A successful exploit can therefore lead to a denial of service. This weakness is classified as CWE‑1188, an insecure default configuration that allows improper resource handling.

Affected Systems

The issue affects NVIDIA graphics stacks running on Linux, including GeForce, RTX, Quadro, NVS, Tesla, and the Virtual GPU Manager. The vulnerability applies to the driver packages distributed for these GPUs; specific version numbers are not disclosed in the provided information.

Risk and Exploitability

With a CVSS score of 6.5, the severity is moderate. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, implying limited or no known exploitation in the wild. Attack details are not described in the advisory; it is inferred that exploitation would likely require elevated privileges or local access to load or reconfigure the driver, making the threat vector likely local rather than remote.

Generated by OpenCVE AI on May 26, 2026 at 19:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest NVIDIA display driver version that addresses the insecure default memory routing in MIG partition management.
  • If a patch is not yet available, disable MIG functionality or avoid reconfiguring GPU partitions until remediation is applied.
  • Restrict access to GPU management utilities and driver files to trusted users only.

Generated by OpenCVE AI on May 26, 2026 at 19:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 11 Jun 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia gpu Display Driver
CPEs cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:linux:*:*
cpe:2.3:a:nvidia:gpu_display_driver:*:*:*:*:*:windows:*:*
Vendors & Products Nvidia gpu Display Driver

Tue, 26 May 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia geforce
Nvidia nvs
Nvidia quadro
Nvidia rtx
Nvidia tesla
Nvidia virtual Gpu Manager
Vendors & Products Nvidia
Nvidia geforce
Nvidia nvs
Nvidia quadro
Nvidia rtx
Nvidia tesla
Nvidia virtual Gpu Manager

Tue, 26 May 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 26 May 2026 19:45:00 +0000

Type Values Removed Values Added
Title Insecure Default GPU Memory Routing Causing Data Corruption and Denial of Service

Tue, 26 May 2026 18:00:00 +0000

Type Values Removed Values Added
Description NVIDIA Display Driver for Linux contains a vulnerability in the Multi-Instance GPU (MIG) partition management, where an insecure default initialization of memory subsystem routing resources could lead to data corruption or a hang during partition reconfiguration. A successful exploit of this vulnerability might lead to denial of service.
Weaknesses CWE-1188
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H'}


Subscriptions

Nvidia Geforce Gpu Display Driver Nvs Quadro Rtx Tesla Virtual Gpu Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-05-27T15:44:16.401Z

Reserved: 2026-01-21T19:09:34.079Z

Link: CVE-2026-24197

cve-icon Vulnrichment

Updated: 2026-05-26T18:53:37.595Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-26T18:16:38.730

Modified: 2026-06-11T02:59:13.100

Link: CVE-2026-24197

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-26T21:15:16Z

Weaknesses
  • CWE-1188

    Initialization of a Resource with an Insecure Default