GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA GPU driver: null pointer dereference in the kernel mode layer causes denial of service

CVSS 4.4CVE-2026-47531NVIDIA / GPU stackcurated

Impact

A null pointer dereference in the kernel mode layer of the GPU driver can be triggered to deny service. It requires high privileges, so the realistic scenario is a privileged node agent or administrator action taking the GPU - and likely the node, since a kernel-mode fault can panic the host - out of service. On a GPU fleet the cost is the drain and reboot, not data exposure: NVIDIA scores it 4.4 for availability only. The Tesla datacenter branch is listed among the affected products. This is a separate flaw from the firmware null pointer dereference in the same bulletin (CVE-2026-47526).

Who can reach it

Local with high privileges: an administrator or root-equivalent process able to call the kernel mode driver interfaces. No network path; not reachable by an unprivileged tenant.

What to do

Update the GPU driver to a version listed as fixed in NVIDIA security bulletin 2026/5861; no fixed versions appear in the record. Replacing the driver unloads the kernel modules, so drain and reboot each GPU node - bundle it with the other fixes from this bulletin rather than taking a separate outage. Given PR:H, this can wait for a planned window.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.