NVIDIA GPU driver: unbounded string operation in the kernel mode layer causes an out-of-bounds read
Impact
An unbounded string operation in the kernel mode layer reads past the end of a buffer. NVIDIA lists the full outcome set up to code execution and privilege escalation, but privileges are already required (PR:H), so the practical value is kernel memory disclosure and crashing the driver on a node an attacker has partly taken. On a GPU host a driver crash usually means losing the running jobs and a reboot to recover.
Who can reach it
Local user who already holds high privileges on the node, Windows or Linux, including the guest driver inside a VM.
What to do
Update the GPU display driver to the fixed branch in NVIDIA bulletin 2026/5861. Drain the node and reboot; this can be batched with the other bulletin 5861 driver fixes in one maintenance window.
References
Related entries
- NVIDIA GPU driver: improper input validation in the kernel mode layerCVE-2026-47522 · NVIDIA GPU Display Driver kernel mode layer (input validation)Medium
- NVIDIA GPU driver: out-of-bounds read in the kernel mode layerCVE-2026-47524 · NVIDIA GPU Display Driver kernel mode layer (out-of-bounds read)Medium
- NVIDIA GPU driver: improper array index validation in the kernel mode layerCVE-2026-47525 · NVIDIA GPU Display Driver kernel mode layer (array index validation)Medium
- NVIDIA GPU firmware: out-of-bounds read reachable from a privileged local userCVE-2026-47527 · NVIDIA GPU firmware (out-of-bounds read)Medium
- NVIDIA GPU firmware: out-of-bounds write reachable from a privileged local userCVE-2026-47538 · NVIDIA GPU firmware (out-of-bounds write)Medium
- NVIDIA vGPU Virtual GPU Manager: incorrect numeric conversion in the kernel mode layerCVE-2026-47539 · NVIDIA vGPU Virtual GPU Manager for Linux (kernel mode layer numeric conversion)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.