GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA GPU driver: improper array index validation in the kernel mode layer

CVSS 6.7CVE-2026-47525NVIDIA / GPU stack+1 more CVEscurated

Impact

The kernel mode layer uses an attacker-influenced array index without validating it, giving out-of-bounds access with code execution, privilege escalation, information disclosure, data tampering and denial of service listed. NVIDIA assigned two ids for this same class of flaw in the same component with the same score and the same fix - CVE-2026-47525 and CVE-2026-47533 in bulletin 2026/5861 - and the operator action is one driver update for both. High privileges are required, so the risk is a privileged-container or compromised-root path reaching host kernel control rather than a tenant escape.

Who can reach it

Local attacker already holding high privileges on the GPU host, Windows or Linux.

What to do

Update the GPU display driver to the fixed branch in NVIDIA bulletin 2026/5861; one roll fixes both ids. Drain the node and reboot to replace the kernel modules.

Also covers 1 CVE

The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.

CVE-2026-47533

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.