NVIDIA GPU driver: unprivileged out-of-bounds writes in the kernel mode layer
Impact
A local user can write past the end of a kernel allocation in the GPU driver. NVIDIA split this across five ids in bulletin 2026/5861 (CVE-2026-47511, 47523, 47530, 47548, 47553) with the same score and the same fix, and the public records give no detail that separates one code path from another. A controlled kernel write from an unprivileged context on a GPU node means host compromise, which on a shared fleet reaches every other tenant on the board and the credentials the node holds.
Who can reach it
Local, unprivileged. Any tenant with a GPU pod or a local user with the NVIDIA device nodes; no authentication.
What to do
Install the driver branch update from NVIDIA bulletin 2026/5861, which closes all five ids; no fixed version appears in this record. The kernel module must be replaced, so drain each GPU node and reboot. Virtual GPU Manager hosts and guest drivers are listed among affected products.
Also covers 4 CVEs
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- NVIDIA GPU driver: out-of-bounds reads leak kernel heap and stack contents to an unprivileged userCVE-2026-47512 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer, kernel memory disclosure)High
- NVIDIA vGPU Manager on Linux: out-of-bounds reads in the host kernel mode layerCVE-2026-47519 · NVIDIA vGPU Virtual GPU Manager for Linux (kernel mode layer)High
- NVIDIA GPU firmware: access of an uninitialized pointer reachable from a local attackerCVE-2026-47528 · NVIDIA GPU firmware as shipped with the GPU Display Driver (uninitialized pointer access)High
- NVIDIA vGPU Manager on Linux: out-of-bounds read in GPU firmwareCVE-2026-47535 · NVIDIA vGPU Virtual GPU Manager for Linux (GPU firmware)High
- NVIDIA GPU driver: integer underflow in the kernel mode layerCVE-2026-47540 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer, size arithmetic)High
- NVIDIA vGPU Manager on Linux: out-of-bounds write in the host kernel mode layerCVE-2026-47541 · NVIDIA vGPU Virtual GPU Manager for Linux (kernel mode layer)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.