NVIDIA Windows GPU driver: use-after-free in the kernel mode layer
Impact
The Windows kernel mode driver uses memory after it has been freed, which an attacker with local access can turn into SYSTEM-level code execution. This matters to GPU operators who run Windows Server instances on Tesla and RTX boards, typically rendering, VDI and vGPU guest fleets rather than Linux training nodes. Where those VMs are handed to customers, this is a guest-local escalation that undermines any in-guest isolation the tenant relies on.
Who can reach it
Local on the Windows system, low privilege. A user or service running on an affected Windows host or guest with the NVIDIA driver installed.
What to do
Install the Windows driver branch listed in NVIDIA bulletin 2026/5861; the record does not name a fixed version. Windows GPU driver updates require a reboot of the instance, so drain each affected VM or host and schedule the restart.
References
Related entries
- NVIDIA Windows GPU driver: unprivileged user causes an out-of-bounds write in the kernel mode layerCVE-2026-47593 · NVIDIA GPU Display Driver for Windows (kernel mode layer)High
- NVIDIA GPU driver: out-of-bounds array access in the kernel mode layerCVE-2026-47507 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer, array indexing)High
- NVIDIA GPU driver: incorrect conversion between numeric types in the kernel mode layerCVE-2026-47508 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer, numeric conversion)High
- NVIDIA GPU driver: integer overflow in size arithmetic leads to an out-of-bounds writeCVE-2026-47510 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer, size arithmetic)High
- NVIDIA GPU driver: unprivileged out-of-bounds writes in the kernel mode layerCVE-2026-47511 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer)High
- NVIDIA GPU driver: out-of-bounds reads leak kernel heap and stack contents to an unprivileged userCVE-2026-47512 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer, kernel memory disclosure)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.