HIGHCVE-2026-24192Published Modified CNA nvidia
CVE-2026-24192: NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause an incorrect conversion between numeric types, leading to a heap buffer overflow
NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause an incorrect conversion between numeric types, leading to a heap buffer overflow. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.
Metrics
- CVSS v3.1
- 7.8
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 13
Affected packages
- NVIDIA / GeForceAll driver versions prior to 595.71.05
- NVIDIA / GeForceAll driver versions prior to 580.159.03
- NVIDIA / GeForceAll driver versions prior to 535.309.01
- NVIDIA / NVIDIA RTX, Quadro, NVSAll driver versions prior to 595.71.05
- NVIDIA / NVIDIA RTX, Quadro, NVSAll driver versions prior to 580.159.03
- NVIDIA / NVIDIA RTX, Quadro, NVSAll driver versions prior to 535.309.01
- NVIDIA / TeslaAll driver versions prior to 595.71.05
- NVIDIA / TeslaAll driver versions prior to 580.159.03
- NVIDIA / TeslaAll driver versions prior to 535.309.01
- NVIDIA / Virtual GPU Manager595.58.02(All versions up to and including the March 2026 release)
- NVIDIA / Virtual GPU Manager595.58.02(All versions prior to and including vGPU 20.0)
- NVIDIA / Virtual GPU Manager580.126.08(All versions prior to and including vGPU 19.4)
- NVIDIA / Virtual GPU Manager535.288.01(All versions prior to and including vGPU 16.13)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HReferences