NVIDIA Linux GPU driver: user-supplied data reaches a format string
Impact
A local user can get attacker-controlled data interpreted as a format string inside the driver. Format string bugs give both a read primitive and, depending on the specifiers reached, a write primitive, which is why NVIDIA rates the outcome as code execution and privilege escalation rather than just a crash. On a GPU node the driver runs with full host privilege, so success means host compromise from inside a tenant workload.
Who can reach it
Local. An unprivileged user or container with access to the NVIDIA device nodes; no authentication beyond a shell on the node.
What to do
Update to the driver branch listed in NVIDIA bulletin 2026/5861; fixed versions are not given in this record. Drain and reboot each affected GPU node so the new kernel-side components load.
References
Related entries
- NVIDIA vGPU Manager: guest-triggered out-of-bounds write in the host kernel mode layerCVE-2026-47495 · NVIDIA vGPU Virtual GPU Manager (kernel mode layer)High
- NVIDIA vGPU Manager: crafted data in the GSP tracing shared buffer causes improper accessCVE-2026-47497 · NVIDIA Virtual GPU Manager (GPU System Processor tracing, guest-host shared buffer)High
- NVIDIA vGPU Manager: crafted guest RPC message causes an out-of-bounds write in the GSP pluginCVE-2026-47498 · NVIDIA vGPU Manager (GPU System Processor plugin, guest RPC handling)High
- NVIDIA vGPU Manager: guest-triggered out-of-bounds read in the host kernel mode layerCVE-2026-47499 · NVIDIA vGPU Virtual GPU Manager (kernel mode layer)High
- NVIDIA GPU driver: use-after-free reachable by an unprivileged user through ordinary driver callsCVE-2026-47500 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer, object lifetime and refcounting)High
- NVIDIA Linux GPU driver: mismatched buffers during event buffer setup cause a kernel out-of-bounds writeCVE-2026-47501 · NVIDIA GPU Display Driver for Linux (kernel mode layer, event buffer setup)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.