NVIDIA GPU driver: out-of-bounds reads leak kernel heap and stack contents to an unprivileged user
Impact
A local user can read past allocation boundaries in the GPU driver and recover kernel heap data and, in one id, stack contents including return addresses and pointers. That is the KASLR-defeating half of an exploit chain: paired with any of the out-of-bounds writes in the same bulletin it turns a blind corruption into a reliable one. NVIDIA split this across five ids (CVE-2026-47512, 47513, 47514, 47545, 47592) with the same score and the same fix, and the records do not distinguish the code paths. On a shared GPU node the leaked data can also include other tenants' buffers.
Who can reach it
Local, unprivileged. Any tenant with a GPU pod or a local user with access to the NVIDIA device nodes.
What to do
Install the driver branch named in NVIDIA bulletin 2026/5861; one update closes all five ids and the record gives no version numbers. Drain and reboot each GPU node, including Virtual GPU Manager hosts and guest driver images.
Also covers 4 CVEs
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- NVIDIA vGPU Manager on Linux: out-of-bounds reads in the host kernel mode layerCVE-2026-47519 · NVIDIA vGPU Virtual GPU Manager for Linux (kernel mode layer)High
- NVIDIA GPU firmware: access of an uninitialized pointer reachable from a local attackerCVE-2026-47528 · NVIDIA GPU firmware as shipped with the GPU Display Driver (uninitialized pointer access)High
- NVIDIA vGPU Manager on Linux: out-of-bounds read in GPU firmwareCVE-2026-47535 · NVIDIA vGPU Virtual GPU Manager for Linux (GPU firmware)High
- NVIDIA GPU driver: integer underflow in the kernel mode layerCVE-2026-47540 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer, size arithmetic)High
- NVIDIA vGPU Manager on Linux: out-of-bounds write in the host kernel mode layerCVE-2026-47541 · NVIDIA vGPU Virtual GPU Manager for Linux (kernel mode layer)High
- NVIDIA Windows GPU driver: untrusted user pointer is dereferenced without validationCVE-2026-47550 · NVIDIA GPU Display Driver for Windows (kernel mode layer, pointer validation)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.