NVIDIA GPU driver: out-of-bounds writes in the kernel mode layer reachable by a privileged local user
Impact
Four out-of-bounds writes in the kernel mode layer of the GPU display driver, which NVIDIA split across CVE-2026-47509, CVE-2026-47529, CVE-2026-47532 and CVE-2026-47537 in bulletin 2026/5861 with the same 6.7 score, the same prerequisites and the same fix. Each lets an already-privileged local user corrupt kernel memory, with code execution, privilege escalation, information disclosure, data tampering and denial of service listed. Because PR:H is required, these are post-compromise depth-in-the-stack bugs rather than tenant escapes: they matter on nodes where root in a container or a privileged device plugin is not meant to equal host kernel control. Two of the four are Linux-only, two affect Windows and Linux; the operator action is identical for all.
Who can reach it
Local attacker who already holds high privileges on the node (root or equivalent, including a privileged container with the GPU devices mapped in). Not reachable by an ordinary unprivileged tenant.
What to do
Update the GPU display driver and guest driver to the fixed branch in NVIDIA bulletin 2026/5861. One driver roll covers all four ids. Drain the node and reboot to unload and replace the kernel modules.
Also covers 3 CVEs
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- NVIDIA GPU driver: unbounded string operation in the kernel mode layer causes an out-of-bounds readCVE-2026-47515 · NVIDIA GPU Display Driver kernel mode layer (unbounded string operation)Medium
- NVIDIA GPU driver: improper input validation in the kernel mode layerCVE-2026-47522 · NVIDIA GPU Display Driver kernel mode layer (input validation)Medium
- NVIDIA GPU driver: out-of-bounds read in the kernel mode layerCVE-2026-47524 · NVIDIA GPU Display Driver kernel mode layer (out-of-bounds read)Medium
- NVIDIA GPU driver: improper array index validation in the kernel mode layerCVE-2026-47525 · NVIDIA GPU Display Driver kernel mode layer (array index validation)Medium
- NVIDIA GPU firmware: out-of-bounds read reachable from a privileged local userCVE-2026-47527 · NVIDIA GPU firmware (out-of-bounds read)Medium
- NVIDIA GPU firmware: out-of-bounds write reachable from a privileged local userCVE-2026-47538 · NVIDIA GPU firmware (out-of-bounds write)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.