CVE-2026-24187Patch(nvidia / gpu_display_driver)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nvidia gpu_display_driver systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gpu_display_driver

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 6 signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-05-19); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
gpu_display_driver

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-05-19: 2Mentions · 2026-05-20: 1Mentions · 2026-05-21: 2Mentions · 2026-05-26: 1Patch / Workaround · 2026-05-19: 2Patch / Workaround · 2026-05-20: 1Patch / Workaround · 2026-05-21: 2Technical Details · 2026-05-19: 2Technical Details · 2026-05-20: 1Technical Details · 2026-05-21: 2Technical Details · 2026-05-26: 105-1905-2005-2105-26
Signal classification2 categories
Patch
583.3%
Disclosure
116.7%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-192
Patch2
2026-05-201
Patch1
2026-05-212
Patch2
2026-05-261
Disclosure1
Full discourse6 posts
  • Pirat_Nation 🔴@Pirat_Nation
    Patch

    NVIDIA has released new updates for its RTX and GTX graphics cards that fix 15 security issues on Windows and Linux computers. The most serious problem is CVE-2026-24187, which affects Linux systems and could let attackers take control of your computer It affects RTX 50, 40, 30, and 20 series cards, plus GTX 16, 10, 900, and some GTX 700 cards. >Windows users with newer cards should install version 596.36 or higher >users with GTX 10, 900, or older GTX 700 cards should use version 582.53. >Linux users should get the latest fixed drivers from NVIDIA.

    Post summary

    NVIDIA released driver updates to address 15 security issues, including CVE‑2026‑24187 which could allow attackers to take control of Linux systems, with specific driver versions recommended for Windows and Linux users.

    286431.3K20794.1K
    339.3K followersView on X
  • precis0x@precisox
    Patch

    NVIDIA lanza actualización de seguridad urgente La compañía acaba de corregir 15 vulnerabilidades en los drivers de sus tarjetas RTX y GTX (Windows y Linux). La más grave es la CVE-2026-24187, que afecta especialmente a Linux y podría permitir a un atacante tomar el control total de tu PC. Tarjetas afectadas: - RTX 50 / 40 / 30 / 20 series - GTX 16 / 10 / 900 y algunos GTX 700 Qué tienes que hacer: → Windows (tarjetas modernas): actualiza a la versión 596.36 o superior → GTX 10 / 900 / GTX 700 antiguas: usa la versión 582.53 → Linux: descarga los drivers corregidos directamente desde NVIDIA No esperes. Actualiza ya antes de que alguien aproveche el fallo.

    Post summary

    NVIDIA lanzó actualizaciones urgentes para 15 vulnerabilidades, incluyendo CVE‑2026‑24187 que permite control total en Linux, con instrucciones claras de actualización y enlaces a drivers corregidos.

    83028102.2K
    14.0K followersView on X
  • yousukezan@yousukezan
    Patch

    NVIDIAがGPU Display Driver向けの大規模セキュリティ更新を公開した。Linux版ではCVSS 8.8のuse-after-free脆弱性CVE-2026-24187が修正され、権限昇格や任意コード実行につながる危険があった。 CVE-2026-24187はLinux向けDisplay Driverに存在し、ローカル攻撃者がuse-after-free状態を引き起こせる。悪用されるとDoS、情報漏えい、データ改ざん、権限昇格、任意コード実行が可能になる。 さらにWindows・Linux両方でCVSS 7.8の複数欠陥も修正された。CVE-2026-24190ではGPUリソースへの不正アクセスが可能で、CVE-2026-24191はWindowsドライバのTOCTOU問題、CVE-2026-24192はLinuxドライバの整数変換不備によるヒープバッファオーバーフロー、CVE-2026-24193は境界外書き込み問題に該当する。 加えてvGPU SoftwareやCloud Gaming環境でもCVE-2026-24200などの重大欠陥が修正された。GPU仮想化マネージャ内のスタックメモリuse-after-freeで、コード実行や権限昇格の恐れがある。影響はVMware vSphere、XenServer、RHEL KVM、Ubuntu、Windows Serverなど広範囲に及ぶ。 対象はGeForce、RTX、Quadro、Teslaを含む多数製品で、管理者にはR595、R590、R580、R570、R535系ドライバの即時更新が推奨されている。 https://securityonline.info/nvidia-gpu-driver-security-update-cve-2026-24187-patch/

    Post summary

    NVIDIA announced a comprehensive GPU driver security update that fixes multiple critical CVEs, including a Linux use‑after‑free (CVE‑2026‑24187) and a stack‑use‑after‑free in vGPU software (CVE‑2026‑24200), and urges users to apply the patches immediately to prevent privilege escalation and code execution.

    060922.9K
    14.5K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    NVIDIA has issued critical security updates for its GPU display drivers and vGPU software to fix a high-severity 8.8 CVSS use-after-free flaw. Patch now! #NVIDIA #GPUDriver #CyberSecurity #InfoSec #VulnerabilityAlert #CVE202624187 #vGPU #PatchNow https://securityonline.info/nvidia-gpu-driver-security-update-cve-2026-24187-patch/ https://t.co/acXTkLq5Cx

    Post summary

    NVIDIA released critical updates for its GPU drivers to fix a high‑severity use‑after‑free flaw (CVE‑2026‑24187), emphasizing the importance of applying the patch.

    04031543
    12.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24187 NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful exploit of this vulnerability might lead to deni… https://www.cve.org/CVERecord?id=CVE-2026-24187

    Post summary

    The text announces a use‑after‑free flaw in NVIDIA’s Linux display driver, with no evidence of a PoC, exploit, active attacks, or patch.

    00010243
    57.5K followersView on X
  • CodeChap@CodeChap
    Patch

    NVIDIA's May bulletin: 15 vulnerabilities, 5 high severity. CVE-2026-24187 on Linux scores 8.8 CVSS - use-after-free, dropped yesterday. Fix is 596.36 on Windows, 595.71.05 on Linux. How many machines in your org are still on the R580 branch? https://nvidia.custhelp.com/app/answers/detail/a_id/5821/~/security-bulletin%3A-nvidia-gpu-display-drivers---may-2026

    Post summary

    The bulletin announces CVE‑2026‑24187, a high‑severity use‑after‑free on Linux, and supplies specific patch versions for Windows and Linux, with no PoC or active exploitation claims.

    00000111
    1.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appnvidiagpu_display_driver-linux-
Appnvidiagpu_display_driver-windows-

Explore more