GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA GPU driver: out-of-bounds array access in the kernel mode layer

CVSS 7.8CVE-2026-47507NVIDIA / GPU stackcurated

Impact

A local user can drive an array index outside its bounds in the kernel mode driver. Because the record does not say whether the access is a read or a write, assume both are possible and treat it as a kernel memory-safety bug reachable from an unprivileged process. On a GPU node that is a tenant-to-host escalation candidate, and the driver is shared by every workload on the board.

Who can reach it

Local, unprivileged. A tenant container or local user with the NVIDIA device nodes open.

What to do

Update to the driver branch from NVIDIA bulletin 2026/5861; no fixed version is in this record. Drain the node and reboot to load the fixed kernel module. Virtual GPU Manager hosts are also listed as affected.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.