NVIDIA GPU driver: improper array index validation in the kernel mode layer
Impact
The kernel mode layer uses an attacker-influenced array index without validating it, giving out-of-bounds access with code execution, privilege escalation, information disclosure, data tampering and denial of service listed. NVIDIA assigned two ids for this same class of flaw in the same component with the same score and the same fix - CVE-2026-47525 and CVE-2026-47533 in bulletin 2026/5861 - and the operator action is one driver update for both. High privileges are required, so the risk is a privileged-container or compromised-root path reaching host kernel control rather than a tenant escape.
Who can reach it
Local attacker already holding high privileges on the GPU host, Windows or Linux.
What to do
Update the GPU display driver to the fixed branch in NVIDIA bulletin 2026/5861; one roll fixes both ids. Drain the node and reboot to replace the kernel modules.
Also covers 1 CVE
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- NVIDIA GPU firmware: out-of-bounds read reachable from a privileged local userCVE-2026-47527 · NVIDIA GPU firmware (out-of-bounds read)Medium
- NVIDIA GPU firmware: out-of-bounds write reachable from a privileged local userCVE-2026-47538 · NVIDIA GPU firmware (out-of-bounds write)Medium
- NVIDIA vGPU Virtual GPU Manager: incorrect numeric conversion in the kernel mode layerCVE-2026-47539 · NVIDIA vGPU Virtual GPU Manager for Linux (kernel mode layer numeric conversion)Medium
- NVIDIA vGPU Virtual GPU Manager: out-of-bounds read in the kernel mode layerCVE-2026-47544 · NVIDIA vGPU Virtual GPU Manager for Linux (kernel mode layer out-of-bounds read)Medium
- NVIDIA GPU firmware: improper input validation reachable from a privileged local userCVE-2026-47546 · NVIDIA GPU firmware (input validation)Medium
- NVIDIA GPU Display Driver (Windows nvlddmkm.sys + Linux nvidia.ko): Improper access control in the kernel-mode layerCVE-2021-1076 · NVIDIA GPU Display Driver (Windows nvlddmkm.sys + Linux nvidia.ko)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.