NVIDIA Linux GPU driver: mismatched buffers during event buffer setup cause a kernel out-of-bounds write
Impact
Event buffer setup accepts a pair of buffers whose sizes do not agree and writes past the end of the smaller one in kernel memory. The caller controls both the trigger and, to a degree, the overflowing content, which makes this one of the more directly exploitable items in the bulletin. Any tenant process that can set up driver events on a shared GPU node can aim at host kernel memory.
Who can reach it
Local, unprivileged. A tenant container or local user with the NVIDIA device nodes open. No authentication needed.
What to do
Apply the driver update from NVIDIA bulletin 2026/5861; the record names no fixed version. The fix lands in the kernel module, so drain each GPU node and reboot. Virtual GPU Manager and guest driver installs are listed as affected too.
References
Related entries
- NVIDIA vGPU Manager: guest-triggered integer overflow leads to memory corruptionCVE-2026-47502 · NVIDIA vGPU Virtual GPU Manager (kernel mode layer, size arithmetic)High
- NVIDIA vGPU plugin: guest RPC with an invalid performance state list size causes an out-of-bounds writeCVE-2026-47503 · NVIDIA Virtual GPU Manager (vGPU plugin, performance state list RPC)High
- NVIDIA Linux driver NGX updater: outdated embedded crypto library is vulnerable to type confusionCVE-2026-47504 · NVIDIA Linux GPU Display Driver (NGX updater, embedded cryptographic library)High
- NVIDIA Windows GPU driver: use-after-free in the kernel mode layerCVE-2026-47505 · NVIDIA GPU Display Driver for Windows (kernel mode layer)High
- NVIDIA GPU driver: out-of-bounds array access in the kernel mode layerCVE-2026-47507 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer, array indexing)High
- NVIDIA GPU driver: incorrect conversion between numeric types in the kernel mode layerCVE-2026-47508 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer, numeric conversion)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.