NVIDIA GPU driver: incorrect conversion between numeric types in the kernel mode layer
Impact
A value crossing between numeric types is converted incorrectly, so a size or index the driver later trusts no longer reflects what was checked. These truncation and sign bugs typically end in a buffer overrun, which is why NVIDIA lists code execution among the outcomes. The caller is an unprivileged local process, so on a shared GPU node any tenant pod is in range.
Who can reach it
Local, unprivileged. A tenant container or user with access to the NVIDIA device nodes.
What to do
Install the driver update referenced in NVIDIA bulletin 2026/5861; no fixed version is given in this record. Drain each GPU node and reboot to load the corrected kernel module.
References
Related entries
- NVIDIA GPU driver: integer overflow in size arithmetic leads to an out-of-bounds writeCVE-2026-47510 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer, size arithmetic)High
- NVIDIA GPU driver: unprivileged out-of-bounds writes in the kernel mode layerCVE-2026-47511 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer)High
- NVIDIA GPU driver: out-of-bounds reads leak kernel heap and stack contents to an unprivileged userCVE-2026-47512 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer, kernel memory disclosure)High
- NVIDIA vGPU Manager on Linux: out-of-bounds reads in the host kernel mode layerCVE-2026-47519 · NVIDIA vGPU Virtual GPU Manager for Linux (kernel mode layer)High
- NVIDIA GPU firmware: access of an uninitialized pointer reachable from a local attackerCVE-2026-47528 · NVIDIA GPU firmware as shipped with the GPU Display Driver (uninitialized pointer access)High
- NVIDIA vGPU Manager on Linux: out-of-bounds read in GPU firmwareCVE-2026-47535 · NVIDIA vGPU Virtual GPU Manager for Linux (GPU firmware)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.