NVIDIA GPU driver: out-of-bounds array access in the kernel mode layer
Impact
A local user can drive an array index outside its bounds in the kernel mode driver. Because the record does not say whether the access is a read or a write, assume both are possible and treat it as a kernel memory-safety bug reachable from an unprivileged process. On a GPU node that is a tenant-to-host escalation candidate, and the driver is shared by every workload on the board.
Who can reach it
Local, unprivileged. A tenant container or local user with the NVIDIA device nodes open.
What to do
Update to the driver branch from NVIDIA bulletin 2026/5861; no fixed version is in this record. Drain the node and reboot to load the fixed kernel module. Virtual GPU Manager hosts are also listed as affected.
References
Related entries
- NVIDIA GPU driver: incorrect conversion between numeric types in the kernel mode layerCVE-2026-47508 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer, numeric conversion)High
- NVIDIA GPU driver: integer overflow in size arithmetic leads to an out-of-bounds writeCVE-2026-47510 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer, size arithmetic)High
- NVIDIA GPU driver: unprivileged out-of-bounds writes in the kernel mode layerCVE-2026-47511 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer)High
- NVIDIA GPU driver: out-of-bounds reads leak kernel heap and stack contents to an unprivileged userCVE-2026-47512 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer, kernel memory disclosure)High
- NVIDIA vGPU Manager on Linux: out-of-bounds reads in the host kernel mode layerCVE-2026-47519 · NVIDIA vGPU Virtual GPU Manager for Linux (kernel mode layer)High
- NVIDIA GPU firmware: access of an uninitialized pointer reachable from a local attackerCVE-2026-47528 · NVIDIA GPU firmware as shipped with the GPU Display Driver (uninitialized pointer access)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.