CVE-2026-24195

HIGH

Nvidia Guest Driver - Improper Input Validation

Title source: rule
STIX 2.1

Description

NVIDIA Display Driver for Linux contains a vulnerability in UVM, where a user could cause improper input validation. A successful exploit of this vulnerability might lead to denial of service.

Scores

CVSS v3 7.1
EPSS 0.0017
EPSS Percentile 6.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (5)
nvidia/gpu_display_driver 535 - 535.309.01
nvidia/gpu_display_driver 535 - 539.72
NVIDIA/Guest driver 580.126.09(All versions prior to and including vGPU 19.4)
NVIDIA/Guest driver 595.58.03(All versions prior to and including vGPU 20.0)
NVIDIA/Guest driver 595.58.03(All versions up to and including the March 2026 release)
Published May 26, 2026
Tracked Since May 26, 2026