NVIDIA GPU driver: divide by zero in the kernel mode layer crashes the driver
Impact
An unprivileged local user can reach a division by zero in the kernel mode layer and crash the GPU driver. Availability only - no data exposure or tampering. The tenancy problem is the usual one: on a node with several GPU workloads, one tenant can remove the device from the others, and getting it back costs a reboot and the in-flight jobs. The Virtual GPU Manager is in the affected list, so a vGPU host can lose all its guests' GPU access.
Who can reach it
Any local low-privileged user able to talk to the GPU driver, Windows or Linux, including a tenant container.
What to do
Update the GPU display driver and vGPU manager to the fixed branch in NVIDIA bulletin 2026/5861. Drain the node and reboot.
References
Related entries
- NVIDIA GPU driver: uninitialized kernel memory is copied back to userspaceCVE-2026-47555 · NVIDIA GPU Display Driver kernel mode layer (uninitialized memory copied to userspace)Medium
- NVIDIA GPU driver for Linux: memory leak in error paths exhausts kernel memoryCVE-2026-47566 · NVIDIA GPU Display Driver for Linux (kernel memory leak in error paths)Medium
- NVIDIA Triton Inference Server: An absolute path traversal reachable from a local low-privileged account reaches codeCVE-2026-47630 · NVIDIA Triton Inference ServerMedium
- Linux kernel amdgpu display core (DC/DM) (drm/amd/display): A NULL pointer dereference in the amdgpu display coreCVE-2026-53135 · Linux kernel amdgpu display core (DC/DM) (drm/amd/display)Medium
- Linux kernel amdgpu display core (DC/DM) (drm/amd/display): Missing or insufficient validation of user-suppliedCVE-2026-53285 · Linux kernel amdgpu display core (DC/DM) (drm/amd/display)Medium
- Linux kernel amdgpu GEM/VM/command-submission ioctl surface (drm/amdgpu): A race condition or locking defectCVE-2026-53293 · Linux kernel amdgpu GEM/VM/command-submission ioctl surface (drm/amdgpu)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.