GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA Linux GPU driver: mapping stays usable after the backing memory is freed and reused

CVSS 7.8CVE-2026-47491NVIDIA / GPU stackcurated

Impact

The driver releases memory resources improperly and leaves a user-accessible mapping pointing at memory that has already been handed out again. That gives an unprivileged local user a read and write window into whatever the allocator placed there next, including another tenant's data or kernel structures. On a shared GPU node this is a direct path from a container to host privilege, and nothing in the container runtime prevents it once the device nodes are exposed.

Who can reach it

Local, unprivileged. Any tenant with a GPU pod or a local user holding /dev/nvidia*. No authentication required.

What to do

Install the fixed driver branch named in NVIDIA bulletin 2026/5861; the record does not state version numbers. Drain each GPU node and reboot it to load the new kernel module.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.