GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA GPU firmware: out-of-bounds read reachable from a privileged local user

CVSS 6.7CVE-2026-47527NVIDIA / GPU stackcurated

Impact

The flaw is in GPU firmware rather than the host kernel driver: a privileged local caller can make the firmware read outside bounds, with NVIDIA listing outcomes up to code execution and privilege escalation. Code execution inside GPU firmware sits below the host OS, so it is not something host-level detection or a reinstall of the driver necessarily clears. NVIDIA's record does not say how the fixed firmware is delivered, so confirm in the bulletin whether your platform takes it with the driver package or as a separate VBIOS image.

Who can reach it

Local attacker already holding high privileges on the GPU node, Windows or Linux.

What to do

Apply the fix listed in NVIDIA bulletin 2026/5861 for your GPU and driver branch. The bulletin, not this entry, is the authority on whether the firmware ships inside the driver package or as a separate update, and on whether the node must be out of service for it. Plan for the GPUs to be idle either way.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.