NVIDIA GPU firmware: null pointer dereference reachable by a privileged local user causes denial of service
Impact
A null pointer dereference in the GPU firmware can be triggered to deny service to the GPU. Because it requires high privileges (CVSS PR:H), this is not a tenant escape path; it matters as a reliability and blast-radius issue - a node-level actor or a buggy privileged agent can knock the GPU offline, and a firmware-level fault typically needs a GPU or node reset rather than a process restart. NVIDIA scores it 4.4, availability only. The Tesla datacenter branch is listed among affected products.
Who can reach it
Local with high privileges: an administrator or root-equivalent process on the GPU node. Not reachable by an unprivileged tenant and not reachable over the network.
What to do
Apply the driver and GPU firmware package listed as fixed in NVIDIA security bulletin 2026/5861 - the record does not state fixed versions. Firmware delivered with the driver stack means taking the node out of service to flash and reset the GPUs, not a daemon restart. Given PR:H, scheduling this with the next planned driver maintenance is reasonable rather than opening an emergency window.
References
Related entries
- NVIDIA GPU driver: null pointer dereference in the kernel mode layer causes denial of serviceCVE-2026-47531 · NVIDIA GPU Display Driver kernel mode layer (Windows and Linux)Medium
- NVIDIA Linux GPU driver: unsanitized version string lets a local user inject text into the kernel logCVE-2026-47562 · NVIDIA GPU Display Driver for Linux (kernel mode layer, unsanitized version string in kernel log)Medium
- NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmware: A null-pointer dereference in SROOT firmware crashesCVE-2025-33197 · NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmwareMedium
- KAI Scheduler: Improper access control in resource allocation (cross-tenant quota abuse)CVE-2026-24176 · KAI SchedulerMedium
- Transformers4Rec: Code exec via insecure deserialization in the pipelineCVE-2026-24232 · Transformers4RecMedium
- NVIDIA License System - Delegated Licensing Service (DLS): Improper authentication in the DLS lets an unauthenticatedCVE-2026-24241 · NVIDIA License System - Delegated Licensing Service (DLS)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.