NVIDIA released fixes for several high-severity vulnerabilities across its Windows and Linux display drivers, installers, and virtual GPU stack that could let attackers escalate privileges, corrupt memory, crash systems, or access sensitive data. The disclosed issues include CVE-2025-23277, an out-of-bounds kernel memory access flaw in NVIDIA Display Drivers for Windows and Linux; CVE-2025-23281, a Windows driver use-after-free tied to concurrent memory handling; CVE-2025-23276, a Windows installer access-control weakness that can yield administrator-level code execution during installation or update; and CVE-2025-23279, a TOCTOU race condition in the Linux and Solaris .run installer that can allow arbitrary code execution as root.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
On June 15, 2026, LevelBlue published an analysis of NVIDIA's Windows kernel display driver fixes, detailing systemic validation flaws across 14 IOCTL handlers and examining CVE-2026-24190, CVE-2026-24182, and CVE-2026-24193. The report recommended upgrading drivers, enforcing Microsoft driver blocklists, monitoring IOCTL activity, and restricting container access to GPU interfaces.
By May 2026, NVIDIA had released patched Windows Kernel Core Display Driver build 596.36. According to LevelBlue's analysis, this build introduced fixes across 35 examined functions, including 19 security-critical changes affecting IOCTL validation, privilege escalation, denial of service, and out-of-bounds write risks.
LevelBlue identified NVIDIA Windows Kernel Core Display Driver build 596.21, dated April 16, 2026, as the vulnerable build used in its analysis of later-fixed kernel flaws. The report ties this build to issues including CVE-2026-24190 and CVE-2026-24182.
NVIDIA released security updates for several vulnerabilities affecting display drivers and virtual GPU software, including CVE-2025-23277, CVE-2025-23281, and CVE-2025-23283. The fixes covered multiple Windows, Linux, guest vGPU, and Virtual GPU Manager branches and platforms.
NVIDIA disclosed CVE-2025-23279 in its July 2025 security bulletin as a local privilege escalation race condition in the .run installer for Linux and Solaris GPU drivers. The company released a fix in its July 2025 security update by adding proper synchronization and advised users to update to the latest GPU Display Driver versions.
NVIDIA remediated CVE-2025-23276, a local privilege escalation flaw in the Windows installer caused by improper access control over installer-created or modified files and directories. NVIDIA advised upgrading to fixed driver branches including R575 577.00+, R570 573.48+, R535 539.41+, and vGPU 18.4 or 16.11 or later.
Qualcomm addressed CVE-2025-27051, a double-free vulnerability in its Windows WLAN Host driver, in its July 2025 Security Bulletin. The flaw could cause severe memory corruption and potentially enable privilege escalation or arbitrary code execution on affected Windows systems using Qualcomm wireless chipsets.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
levelblue.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourcezeropath.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.