GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA Windows GPU driver: use-after-free in the kernel mode layer

CVSS 7.8CVE-2026-47505NVIDIA / GPU stackcurated

Impact

The Windows kernel mode driver uses memory after it has been freed, which an attacker with local access can turn into SYSTEM-level code execution. This matters to GPU operators who run Windows Server instances on Tesla and RTX boards, typically rendering, VDI and vGPU guest fleets rather than Linux training nodes. Where those VMs are handed to customers, this is a guest-local escalation that undermines any in-guest isolation the tenant relies on.

Who can reach it

Local on the Windows system, low privilege. A user or service running on an affected Windows host or guest with the NVIDIA driver installed.

What to do

Install the Windows driver branch listed in NVIDIA bulletin 2026/5861; the record does not name a fixed version. Windows GPU driver updates require a reboot of the instance, so drain each affected VM or host and schedule the restart.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.