GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA GPU firmware: access of an uninitialized pointer reachable from a local attacker

CVSS 7.8CVE-2026-47528NVIDIA / GPU stackcurated

Impact

The flaw is in firmware rather than in the host-side driver, so the faulting code runs on the GPU itself, below the operating system's view. An attacker who reaches it gets execution or corruption in a context that host-level EDR and kernel hardening do not see, and that persists across a process or container restart until the board is reset. NVIDIA ships this firmware inside the driver package, so the remedy is still a driver update rather than a separate flashing step, but it does mean the GPU must be reinitialized for the new firmware to take effect.

Who can reach it

Local. An attacker able to submit work to the GPU through the driver on an affected node, including a tenant container with the device nodes; Virtual GPU Manager hosts are also listed.

What to do

Install the driver package from NVIDIA bulletin 2026/5861, which carries the updated GPU firmware; no fixed version is stated in this record. The GPU has to be reinitialized with the new firmware, so drain the node and reboot rather than only reloading the kernel module.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.