NVIDIA GPU driver: use-after-free reachable by an unprivileged user through ordinary driver calls
Impact
Objects in the kernel mode layer are freed while still referenced, in one id because reference counts are not cleaned up on an error path and in others simply by issuing a sequence of driver commands. NVIDIA assigned six ids to this class across Windows and Linux in bulletin 2026/5861 (CVE-2026-47500, 47516, 47551, 47589, 47590, 47594), all at the same score with the same fix, and the records give no detail that would lead an operator to act differently on any one of them. Use-after-free in a privileged GPU kernel module is the standard container-to-host-root path on a multi-tenant node, and error paths are easy for a tenant to force on demand.
Who can reach it
Local, unprivileged. Any tenant with a GPU pod or a local user with the NVIDIA device nodes; no authentication required.
What to do
Apply the driver branch update from NVIDIA bulletin 2026/5861, which covers all six ids; the record states no fixed version. Drain each GPU node and reboot. Guest drivers inside VMs and Virtual GPU Manager hosts are listed as affected and need the same update.
Also covers 5 CVEs
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- NVIDIA Linux GPU driver: mismatched buffers during event buffer setup cause a kernel out-of-bounds writeCVE-2026-47501 · NVIDIA GPU Display Driver for Linux (kernel mode layer, event buffer setup)High
- NVIDIA vGPU Manager: guest-triggered integer overflow leads to memory corruptionCVE-2026-47502 · NVIDIA vGPU Virtual GPU Manager (kernel mode layer, size arithmetic)High
- NVIDIA vGPU plugin: guest RPC with an invalid performance state list size causes an out-of-bounds writeCVE-2026-47503 · NVIDIA Virtual GPU Manager (vGPU plugin, performance state list RPC)High
- NVIDIA Linux driver NGX updater: outdated embedded crypto library is vulnerable to type confusionCVE-2026-47504 · NVIDIA Linux GPU Display Driver (NGX updater, embedded cryptographic library)High
- NVIDIA Windows GPU driver: use-after-free in the kernel mode layerCVE-2026-47505 · NVIDIA GPU Display Driver for Windows (kernel mode layer)High
- NVIDIA GPU driver: out-of-bounds array access in the kernel mode layerCVE-2026-47507 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer, array indexing)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.