NVIDIA GPU firmware: out-of-bounds write reachable from a privileged local user
Impact
An out-of-bounds write inside GPU firmware, reachable by a local caller that already has high privileges, with code execution, privilege escalation, information disclosure, data tampering and denial of service listed. Memory corruption in firmware is the more serious of the two firmware items in bulletin 5861: it is a write primitive beneath the host OS on a device that is shared or recycled between tenants. NVIDIA's record does not describe the delivery mechanism for the fixed firmware.
Who can reach it
Local attacker with high privileges on the GPU node, Windows or Linux.
What to do
Apply the fix from NVIDIA bulletin 2026/5861 for your GPU model and branch. Check the bulletin for whether the firmware is carried by the driver package or needs a separate flash, and schedule the node out of service for it. No mitigation is documented short of the update.
References
Related entries
- NVIDIA vGPU Virtual GPU Manager: incorrect numeric conversion in the kernel mode layerCVE-2026-47539 · NVIDIA vGPU Virtual GPU Manager for Linux (kernel mode layer numeric conversion)Medium
- NVIDIA vGPU Virtual GPU Manager: out-of-bounds read in the kernel mode layerCVE-2026-47544 · NVIDIA vGPU Virtual GPU Manager for Linux (kernel mode layer out-of-bounds read)Medium
- NVIDIA GPU firmware: improper input validation reachable from a privileged local userCVE-2026-47546 · NVIDIA GPU firmware (input validation)Medium
- NVIDIA GPU Display Driver (Windows nvlddmkm.sys + Linux nvidia.ko): Improper access control in the kernel-mode layerCVE-2021-1076 · NVIDIA GPU Display Driver (Windows nvlddmkm.sys + Linux nvidia.ko)Medium
- NVIDIA GPU Display Driver (Windows nvlddmkm.sys + Linux nvidia.ko): Reference-count mishandling on a driver resourceCVE-2021-1077 · NVIDIA GPU Display Driver (Windows nvlddmkm.sys + Linux nvidia.ko)Medium
- GPU Display Driver: Local privesc (kernel buffer overflow)CVE-2023-0198 · GPU Display DriverMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.