
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24199 is a race condition vulnerability in the NVIDIA Display Driver for Linux, specifically within a kernel module, where a local user can trigger a denial of service by reordering compiler or processor memory instructions. It was published on May 26, 2026, and affects NVIDIA GPU Display Driver for Linux across three driver branches: versions 535.x before 535.309.01, 580.x before 580.159.03, and 595.x before 595.71.05. Affected GPU product lines include GeForce, RTX, Quadro, NVS, Tesla, and vGPU configurations. The vulnerability carries a CVSS v3.1 base score of 4.7 (Medium), assigned by NVIDIA Corporation (GitHub Advisory, NVIDIA Advisory).
The vulnerability is classified as CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization / Race Condition). It resides in a Linux kernel module of the NVIDIA GPU Display Driver, where insufficient memory ordering controls allow a local user to manipulate the sequence of compiler or processor memory instructions, creating a timing window that corrupts shared resource state. Exploitation requires local access with low privileges and involves high attack complexity due to the timing-dependent nature of race conditions. No public proof-of-concept or detailed technical write-up has been identified at this time (GitHub Advisory, NVIDIA Advisory).
Successful exploitation of this vulnerability can result in a denial of service, potentially causing the affected Linux system to crash or become unresponsive. The impact is limited to availability — there is no confidentiality or integrity impact, and the scope is unchanged, meaning the vulnerability does not enable privilege escalation or lateral movement to other system components. Systems running affected NVIDIA drivers across GeForce, RTX, Quadro, NVS, Tesla, and vGPU product lines on Linux are at risk (GitHub Advisory, NVIDIA Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.011% (2nd percentile), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local access with low privileges and high attack complexity, further limiting practical exploitability (GitHub Advisory, NVIDIA Advisory).
NVIDIA has released patched driver versions addressing this vulnerability. Users should upgrade to the following versions or later: 535.309.01 (for the 535.x branch), 580.159.03 (for the 580.x branch), or 595.71.05 (for the 595.x branch). For vGPU environments, updated Virtual GPU Manager and Guest Driver packages are also available. As interim measures, limiting local user access to systems running the vulnerable driver and applying kernel hardening configurations can reduce the attack surface. SUSE has also issued a security update (SUSE-SU-2026:21878-1) for affected NVIDIA open driver packages, and Amazon Linux 2023 has published a corresponding advisory (NVIDIA Advisory, GitHub Advisory).
Gaming on Linux covered the disclosure as part of a broader report on NVIDIA's May 2026 GPU driver security fixes, noting multiple vulnerabilities addressed in the release (Gaming on Linux). IRC-Junkie reported that NVIDIA fixed 14 vulnerabilities across its Windows and Linux drivers in this release cycle. SUSE and Red Hat both issued downstream advisories, reflecting standard enterprise Linux vendor response to the disclosure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."