GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA Linux driver NGX updater: outdated embedded crypto library is vulnerable to type confusion

CVSS 7.8CVE-2026-47504NVIDIA / GPU stackcurated

Impact

The NGX updater ships its own copy of a cryptographic library that is old enough to carry a known type confusion flaw, and that copy is reachable from local user input. Because the bug lives in a bundled library rather than in NVIDIA code, patching the distribution's system crypto packages does nothing; only the driver update replaces it. NGX is not needed on most headless training and inference nodes, so operators who do not install the NGX components have less exposure here than the CVSS alone suggests.

Who can reach it

Local. A user able to drive the NGX updater on a node where those components are installed.

What to do

Install the driver package from NVIDIA bulletin 2026/5861, which carries the refreshed embedded library; no fixed version appears in this record. Where NGX is not used, leaving those optional components uninstalled removes the exposed path. A full driver update still requires draining the node and reloading or rebooting.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.