GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA GPU driver: unprivileged out-of-bounds writes in the kernel mode layer

CVSS 7.8CVE-2026-47511NVIDIA / GPU stack+4 more CVEscurated

Impact

A local user can write past the end of a kernel allocation in the GPU driver. NVIDIA split this across five ids in bulletin 2026/5861 (CVE-2026-47511, 47523, 47530, 47548, 47553) with the same score and the same fix, and the public records give no detail that separates one code path from another. A controlled kernel write from an unprivileged context on a GPU node means host compromise, which on a shared fleet reaches every other tenant on the board and the credentials the node holds.

Who can reach it

Local, unprivileged. Any tenant with a GPU pod or a local user with the NVIDIA device nodes; no authentication.

What to do

Install the driver branch update from NVIDIA bulletin 2026/5861, which closes all five ids; no fixed version appears in this record. The kernel module must be replaced, so drain each GPU node and reboot. Virtual GPU Manager hosts and guest drivers are listed among affected products.

Also covers 4 CVEs

The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.

CVE-2026-47523CVE-2026-47530CVE-2026-47548CVE-2026-47553

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.