NVIDIA Linux GPU driver: mapping stays usable after the backing memory is freed and reused
Impact
The driver releases memory resources improperly and leaves a user-accessible mapping pointing at memory that has already been handed out again. That gives an unprivileged local user a read and write window into whatever the allocator placed there next, including another tenant's data or kernel structures. On a shared GPU node this is a direct path from a container to host privilege, and nothing in the container runtime prevents it once the device nodes are exposed.
Who can reach it
Local, unprivileged. Any tenant with a GPU pod or a local user holding /dev/nvidia*. No authentication required.
What to do
Install the fixed driver branch named in NVIDIA bulletin 2026/5861; the record does not state version numbers. Drain each GPU node and reboot it to load the new kernel module.
References
Related entries
- NVIDIA vGPU: a guest can reach privileged host GPU resources it is not authorized forCVE-2026-47493 · NVIDIA vGPU software (GPU kernel driver, guest access to host GPU resources)High
- NVIDIA Linux GPU driver: user-supplied data reaches a format stringCVE-2026-47494 · NVIDIA GPU Display Driver for Linux (format string handling)High
- NVIDIA vGPU Manager: guest-triggered out-of-bounds write in the host kernel mode layerCVE-2026-47495 · NVIDIA vGPU Virtual GPU Manager (kernel mode layer)High
- NVIDIA vGPU Manager: crafted data in the GSP tracing shared buffer causes improper accessCVE-2026-47497 · NVIDIA Virtual GPU Manager (GPU System Processor tracing, guest-host shared buffer)High
- NVIDIA vGPU Manager: crafted guest RPC message causes an out-of-bounds write in the GSP pluginCVE-2026-47498 · NVIDIA vGPU Manager (GPU System Processor plugin, guest RPC handling)High
- NVIDIA vGPU Manager: guest-triggered out-of-bounds read in the host kernel mode layerCVE-2026-47499 · NVIDIA vGPU Virtual GPU Manager (kernel mode layer)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.