GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA GPU driver: integer overflow in size arithmetic leads to an out-of-bounds write

CVSS 7.8CVE-2026-47510NVIDIA / GPU stack+1 more CVEscurated

Impact

A caller-controlled size calculation overflows, so the driver allocates less than it later writes and overruns the buffer; in one id the overrun lands in GPU memory. NVIDIA assigned two ids for this pattern in bulletin 2026/5861 (CVE-2026-47510 and CVE-2026-47556) with the same score and the same driver fix. Overflowed length checks are attractive to exploit because the attacker picks the arithmetic, and on a GPU node the driver sits at host privilege above every tenant workload.

Who can reach it

Local, unprivileged. Any tenant with a GPU pod or a local user holding the NVIDIA device nodes.

What to do

Apply the driver update from NVIDIA bulletin 2026/5861; the record does not state fixed versions. One update covers both ids. Drain each GPU node and reboot; update the guest driver inside affected VMs as well.

Also covers 1 CVE

The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.

CVE-2026-47556

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.