GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA Linux GPU driver: user-supplied data reaches a format string

CVSS 7.8CVE-2026-47494NVIDIA / GPU stackcurated

Impact

A local user can get attacker-controlled data interpreted as a format string inside the driver. Format string bugs give both a read primitive and, depending on the specifiers reached, a write primitive, which is why NVIDIA rates the outcome as code execution and privilege escalation rather than just a crash. On a GPU node the driver runs with full host privilege, so success means host compromise from inside a tenant workload.

Who can reach it

Local. An unprivileged user or container with access to the NVIDIA device nodes; no authentication beyond a shell on the node.

What to do

Update to the driver branch listed in NVIDIA bulletin 2026/5861; fixed versions are not given in this record. Drain and reboot each affected GPU node so the new kernel-side components load.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.