GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA GPU firmware: null pointer dereference reachable by a privileged local user causes denial of service

CVSS 4.4CVE-2026-47526NVIDIA / GPU stackcurated

Impact

A null pointer dereference in the GPU firmware can be triggered to deny service to the GPU. Because it requires high privileges (CVSS PR:H), this is not a tenant escape path; it matters as a reliability and blast-radius issue - a node-level actor or a buggy privileged agent can knock the GPU offline, and a firmware-level fault typically needs a GPU or node reset rather than a process restart. NVIDIA scores it 4.4, availability only. The Tesla datacenter branch is listed among affected products.

Who can reach it

Local with high privileges: an administrator or root-equivalent process on the GPU node. Not reachable by an unprivileged tenant and not reachable over the network.

What to do

Apply the driver and GPU firmware package listed as fixed in NVIDIA security bulletin 2026/5861 - the record does not state fixed versions. Firmware delivered with the driver stack means taking the node out of service to flash and reset the GPUs, not a daemon restart. Given PR:H, scheduling this with the next planned driver maintenance is reasonable rather than opening an emergency window.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.