NVIDIA Linux driver NGX updater: outdated embedded crypto library is vulnerable to type confusion
Impact
The NGX updater ships its own copy of a cryptographic library that is old enough to carry a known type confusion flaw, and that copy is reachable from local user input. Because the bug lives in a bundled library rather than in NVIDIA code, patching the distribution's system crypto packages does nothing; only the driver update replaces it. NGX is not needed on most headless training and inference nodes, so operators who do not install the NGX components have less exposure here than the CVSS alone suggests.
Who can reach it
Local. A user able to drive the NGX updater on a node where those components are installed.
What to do
Install the driver package from NVIDIA bulletin 2026/5861, which carries the refreshed embedded library; no fixed version appears in this record. Where NGX is not used, leaving those optional components uninstalled removes the exposed path. A full driver update still requires draining the node and reloading or rebooting.
References
Related entries
- NVIDIA Windows GPU driver: use-after-free in the kernel mode layerCVE-2026-47505 · NVIDIA GPU Display Driver for Windows (kernel mode layer)High
- NVIDIA GPU driver: out-of-bounds array access in the kernel mode layerCVE-2026-47507 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer, array indexing)High
- NVIDIA GPU driver: incorrect conversion between numeric types in the kernel mode layerCVE-2026-47508 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer, numeric conversion)High
- NVIDIA GPU driver: integer overflow in size arithmetic leads to an out-of-bounds writeCVE-2026-47510 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer, size arithmetic)High
- NVIDIA GPU driver: unprivileged out-of-bounds writes in the kernel mode layerCVE-2026-47511 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer)High
- NVIDIA GPU driver: out-of-bounds reads leak kernel heap and stack contents to an unprivileged userCVE-2026-47512 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer, kernel memory disclosure)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.