CVE-2026-24187
NVIDIA Linux driver use-after-free enables local privilege escalation and possible RCE.
Is CVE-2026-24187 being exploited?
Not confirmed. CVE-2026-24187 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.19% probability of exploitation in the next 30 days.
How severe is CVE-2026-24187?
CVE-2026-24187 is rated High with a CVSS score of 8.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.
Is there a patch for CVE-2026-24187?
Yes. A fix has been recorded for CVE-2026-24187. The vendor advisory is the authority on the exact fixed version — apply it from there rather than from a summary.
What does CVE-2026-24187 affect?
CVE-2026-24187 affects NVIDIA Linux Display Driver, NVIDIA GPU driver for Linux. Confirm the exact affected versions against the vendor advisory before deciding you are exposed.
What should I do about CVE-2026-24187?
Update to driver when a patch is released; monitor NVIDIA advisories.
Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.
Local attacker could exploit use-after-free in NVIDIA Linux driver to escalate privileges, crash, disclose data, or take control of kernel state.
Patch when possible
- affectedAll driver versions prior to 595.71.05
- affectedAll driver versions prior to 580.159.03
- affectedAll driver versions prior to 535.309.01
- affected595.58.03(All versions prior to and including vGPU 20.0)
- affected580.126.09(All versions prior to and including vGPU 19.4)
- affected535.288.01(All versions prior to and including vGPU 16.13)
- affected595.58.03(All versions up to and including the March 2026 release)
- affectedAll driver versions prior to 595.71.05
- affectedAll driver versions prior to 580.159.03
- affectedAll driver versions prior to 535.309.01
- affectedAll driver versions prior to 595.71.05
- affectedAll driver versions prior to 580.159.03
- affectedAll driver versions prior to 535.309.01
- affected595.58.02(All versions up to and including the March 2026 release)
- affected595.58.02(All versions prior to and including vGPU 20.0)
- affected580.126.08(All versions prior to and including vGPU 19.4)
- affected535.288.01(All versions prior to and including vGPU 16.13)
As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.