GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA GPU driver: incorrect conversion between numeric types in the kernel mode layer

CVSS 7.8CVE-2026-47508NVIDIA / GPU stackcurated

Impact

A value crossing between numeric types is converted incorrectly, so a size or index the driver later trusts no longer reflects what was checked. These truncation and sign bugs typically end in a buffer overrun, which is why NVIDIA lists code execution among the outcomes. The caller is an unprivileged local process, so on a shared GPU node any tenant pod is in range.

Who can reach it

Local, unprivileged. A tenant container or user with access to the NVIDIA device nodes.

What to do

Install the driver update referenced in NVIDIA bulletin 2026/5861; no fixed version is given in this record. Drain each GPU node and reboot to load the corrected kernel module.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.