NVIDIA GPU driver: null pointer dereference in the kernel mode layer causes denial of service
Impact
A null pointer dereference in the kernel mode layer of the GPU driver can be triggered to deny service. It requires high privileges, so the realistic scenario is a privileged node agent or administrator action taking the GPU - and likely the node, since a kernel-mode fault can panic the host - out of service. On a GPU fleet the cost is the drain and reboot, not data exposure: NVIDIA scores it 4.4 for availability only. The Tesla datacenter branch is listed among the affected products. This is a separate flaw from the firmware null pointer dereference in the same bulletin (CVE-2026-47526).
Who can reach it
Local with high privileges: an administrator or root-equivalent process able to call the kernel mode driver interfaces. No network path; not reachable by an unprivileged tenant.
What to do
Update the GPU driver to a version listed as fixed in NVIDIA security bulletin 2026/5861; no fixed versions appear in the record. Replacing the driver unloads the kernel modules, so drain and reboot each GPU node - bundle it with the other fixes from this bulletin rather than taking a separate outage. Given PR:H, this can wait for a planned window.
References
Related entries
- NVIDIA Linux GPU driver: unsanitized version string lets a local user inject text into the kernel logCVE-2026-47562 · NVIDIA GPU Display Driver for Linux (kernel mode layer, unsanitized version string in kernel log)Medium
- NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmware: A null-pointer dereference in SROOT firmware crashesCVE-2025-33197 · NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmwareMedium
- KAI Scheduler: Improper access control in resource allocation (cross-tenant quota abuse)CVE-2026-24176 · KAI SchedulerMedium
- Transformers4Rec: Code exec via insecure deserialization in the pipelineCVE-2026-24232 · Transformers4RecMedium
- NVIDIA License System - Delegated Licensing Service (DLS): Improper authentication in the DLS lets an unauthenticatedCVE-2026-24241 · NVIDIA License System - Delegated Licensing Service (DLS)Medium
- GeForce NOW Android app: Info disclosure / code exec via implicit intentCVE-2023-31014 · GeForce NOW Android appMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.