NVIDIA GPU driver: out-of-bounds read in the kernel mode layer
Impact
The kernel mode layer reads outside allocated bounds when handling input from a privileged local caller, leaking kernel memory or faulting. NVIDIA's description does not name the ioctl or subsystem, so treat the exposure as kernel memory disclosure and driver denial of service on a node the attacker already has privileges on. A faulted GPU driver on a training node generally costs the job and a reboot.
Who can reach it
Local attacker with high privileges already on the host, Windows or Linux.
What to do
Update the GPU display driver to the fixed branch in NVIDIA bulletin 2026/5861, then drain the node and reboot. Roll it with the rest of the bulletin rather than separately.
References
Related entries
- NVIDIA GPU driver: improper array index validation in the kernel mode layerCVE-2026-47525 · NVIDIA GPU Display Driver kernel mode layer (array index validation)Medium
- NVIDIA GPU firmware: out-of-bounds read reachable from a privileged local userCVE-2026-47527 · NVIDIA GPU firmware (out-of-bounds read)Medium
- NVIDIA GPU firmware: out-of-bounds write reachable from a privileged local userCVE-2026-47538 · NVIDIA GPU firmware (out-of-bounds write)Medium
- NVIDIA vGPU Virtual GPU Manager: incorrect numeric conversion in the kernel mode layerCVE-2026-47539 · NVIDIA vGPU Virtual GPU Manager for Linux (kernel mode layer numeric conversion)Medium
- NVIDIA vGPU Virtual GPU Manager: out-of-bounds read in the kernel mode layerCVE-2026-47544 · NVIDIA vGPU Virtual GPU Manager for Linux (kernel mode layer out-of-bounds read)Medium
- NVIDIA GPU firmware: improper input validation reachable from a privileged local userCVE-2026-47546 · NVIDIA GPU firmware (input validation)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.