GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA GPU driver: use-after-free reachable by an unprivileged user through ordinary driver calls

CVSS 7.8CVE-2026-47500NVIDIA / GPU stack+5 more CVEscurated

Impact

Objects in the kernel mode layer are freed while still referenced, in one id because reference counts are not cleaned up on an error path and in others simply by issuing a sequence of driver commands. NVIDIA assigned six ids to this class across Windows and Linux in bulletin 2026/5861 (CVE-2026-47500, 47516, 47551, 47589, 47590, 47594), all at the same score with the same fix, and the records give no detail that would lead an operator to act differently on any one of them. Use-after-free in a privileged GPU kernel module is the standard container-to-host-root path on a multi-tenant node, and error paths are easy for a tenant to force on demand.

Who can reach it

Local, unprivileged. Any tenant with a GPU pod or a local user with the NVIDIA device nodes; no authentication required.

What to do

Apply the driver branch update from NVIDIA bulletin 2026/5861, which covers all six ids; the record states no fixed version. Drain each GPU node and reboot. Guest drivers inside VMs and Virtual GPU Manager hosts are listed as affected and need the same update.

Also covers 5 CVEs

The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.

CVE-2026-47516CVE-2026-47551CVE-2026-47589CVE-2026-47590CVE-2026-47594

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.