GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA GPU firmware: out-of-bounds write reachable from a privileged local user

CVSS 6.7CVE-2026-47538NVIDIA / GPU stackcurated

Impact

An out-of-bounds write inside GPU firmware, reachable by a local caller that already has high privileges, with code execution, privilege escalation, information disclosure, data tampering and denial of service listed. Memory corruption in firmware is the more serious of the two firmware items in bulletin 5861: it is a write primitive beneath the host OS on a device that is shared or recycled between tenants. NVIDIA's record does not describe the delivery mechanism for the fixed firmware.

Who can reach it

Local attacker with high privileges on the GPU node, Windows or Linux.

What to do

Apply the fix from NVIDIA bulletin 2026/5861 for your GPU model and branch. Check the bulletin for whether the firmware is carried by the driver package or needs a separate flash, and schedule the node out of service for it. No mitigation is documented short of the update.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.