GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA GPU driver: unbounded string operation in the kernel mode layer causes an out-of-bounds read

CVSS 6.7CVE-2026-47515NVIDIA / GPU stackcurated

Impact

An unbounded string operation in the kernel mode layer reads past the end of a buffer. NVIDIA lists the full outcome set up to code execution and privilege escalation, but privileges are already required (PR:H), so the practical value is kernel memory disclosure and crashing the driver on a node an attacker has partly taken. On a GPU host a driver crash usually means losing the running jobs and a reboot to recover.

Who can reach it

Local user who already holds high privileges on the node, Windows or Linux, including the guest driver inside a VM.

What to do

Update the GPU display driver to the fixed branch in NVIDIA bulletin 2026/5861. Drain the node and reboot; this can be batched with the other bulletin 5861 driver fixes in one maintenance window.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.