NVIDIA GPU driver: improper input validation in the kernel mode layer
Impact
Improper input validation in the kernel mode layer of the GPU display driver, which NVIDIA split across CVE-2026-47522, CVE-2026-47542 and CVE-2026-47543 in bulletin 2026/5861 - same component, same 6.7 score, same prerequisites, same fix. A privileged local user can feed the driver values it does not check, with outcomes up to kernel code execution and privilege escalation. NVIDIA does not name the affected entry points, so the honest reading is: on a node where an attacker already has high privileges, the GPU driver does not hold the line. One driver update closes all three.
Who can reach it
Local attacker with high privileges on the host, Windows or Linux.
What to do
Update the GPU display driver to the fixed branch in NVIDIA bulletin 2026/5861. Drain the node and reboot; a single roll covers all three ids.
Also covers 2 CVEs
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- NVIDIA GPU driver: out-of-bounds read in the kernel mode layerCVE-2026-47524 · NVIDIA GPU Display Driver kernel mode layer (out-of-bounds read)Medium
- NVIDIA GPU driver: improper array index validation in the kernel mode layerCVE-2026-47525 · NVIDIA GPU Display Driver kernel mode layer (array index validation)Medium
- NVIDIA GPU firmware: out-of-bounds read reachable from a privileged local userCVE-2026-47527 · NVIDIA GPU firmware (out-of-bounds read)Medium
- NVIDIA GPU firmware: out-of-bounds write reachable from a privileged local userCVE-2026-47538 · NVIDIA GPU firmware (out-of-bounds write)Medium
- NVIDIA vGPU Virtual GPU Manager: incorrect numeric conversion in the kernel mode layerCVE-2026-47539 · NVIDIA vGPU Virtual GPU Manager for Linux (kernel mode layer numeric conversion)Medium
- NVIDIA vGPU Virtual GPU Manager: out-of-bounds read in the kernel mode layerCVE-2026-47544 · NVIDIA vGPU Virtual GPU Manager for Linux (kernel mode layer out-of-bounds read)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.