NVIDIA GPU driver for Linux: unprivileged NULL pointer dereferences crash the driver
Impact
Three NULL pointer dereferences in the Linux GPU driver that an unprivileged local user can trigger, which NVIDIA split across CVE-2026-47517, CVE-2026-47549 and CVE-2026-47557 in bulletin 2026/5861 - same product, same 5.5 availability-only score, same fix, same operator action. CVE-2026-47517 is described as a crafted ioctl; all three end in a driver crash. In a multi-tenant cluster this is the cheapest denial of service available to a tenant: one pod can take the GPU, and often the node, away from everyone else sharing it, and the recovery is a reboot that kills the co-tenants' jobs. No confidentiality or integrity impact.
Who can reach it
Any local unprivileged user with access to the NVIDIA device nodes, including inside a guest VM or a tenant GPU container.
What to do
Update the Linux GPU display driver, guest driver and vGPU manager to the fixed branch in NVIDIA bulletin 2026/5861; one roll closes all three ids. Drain the node and reboot to replace the kernel modules.
Also covers 2 CVEs
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- NVIDIA GPU driver: divide by zero in the kernel mode layer crashes the driverCVE-2026-47534 · NVIDIA GPU Display Driver kernel mode layer (divide by zero)Medium
- NVIDIA GPU driver: uninitialized kernel memory is copied back to userspaceCVE-2026-47555 · NVIDIA GPU Display Driver kernel mode layer (uninitialized memory copied to userspace)Medium
- NVIDIA GPU driver for Linux: memory leak in error paths exhausts kernel memoryCVE-2026-47566 · NVIDIA GPU Display Driver for Linux (kernel memory leak in error paths)Medium
- NVIDIA Triton Inference Server: An absolute path traversal reachable from a local low-privileged account reaches codeCVE-2026-47630 · NVIDIA Triton Inference ServerMedium
- Linux kernel amdgpu display core (DC/DM) (drm/amd/display): A NULL pointer dereference in the amdgpu display coreCVE-2026-53135 · Linux kernel amdgpu display core (DC/DM) (drm/amd/display)Medium
- Linux kernel amdgpu display core (DC/DM) (drm/amd/display): Missing or insufficient validation of user-suppliedCVE-2026-53285 · Linux kernel amdgpu display core (DC/DM) (drm/amd/display)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.