NVIDIA GPU Display Driver Security Bulletin (CVE-2026-24187)

Dear NVIDIA Product Security / Support Team,

We are reaching out regarding Security Bulletin: NVIDIA GPU Display Drivers - May 2026, specifically CVE-2026-24187 (use-after-free, CVSS 8.8).

Our GPUs are deployed in Dell PowerEdge servers (DSS8440, R750xa, R760xa, R760, XE9680) within a financial-sector customer’s air-gapped (dark site / closed network) environment. We do not hold an NVIDIA Enterprise support license, and Dell support directed us to contact NVIDIA directly regarding this CVE.

We would appreciate your guidance on the following:

  1. Is patching mandatory for systems in a fully air-gapped, closed-network environment with no external connectivity, given that CVE-2026-24187 has a local attack vector (AV:L)? We want to understand the residual risk in this deployment context.

  2. Could you confirm the minimum patched driver version for each branch relevant to our inventory below?

  3. Specifically, is driver version 575.57.08 (used on an R760xa with H100 NVL GPUs) affected by CVE-2026-24187, and if so, what is the minimum version we need to update to?

Our current inventory:

  • All OS Version is RHEL 9.8
  • DSS8440 / NVIDIA A100 80GB (x8) — driver 580.173.02
  • DSS8440 / NVIDIA A100 80GB (x8, x3 units) — driver 535.261.03
  • R750xa / NVIDIA L40S (x4) — driver 535.129.03
  • R750xa / NVIDIA L40S (x4) — driver 580.173.02
  • R760xa / NVIDIA H100 NVL 94GB (x4) — driver 575.57.08
  • R760 / NVIDIA L4 24GB (x1, x3 units) — driver 580.65.06
  • XE9680 / NVIDIA HGX H100 SXM 80GB (x8) — driver 580.173.02

For each entry, could you confirm whether the installed version already includes the fix, or whether an update is required, and if so, to which target version?

Given that this environment is air-gapped, any driver updates must go through an offline transfer and change-control process, so we would like to confirm the exact requirement before scheduling that work.

Thank you in advance for your assistance.

Best regards,