GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA GPU firmware: improper input validation reachable from a privileged local user

CVSS 6.7CVE-2026-47546NVIDIA / GPU stack+1 more CVEscurated

Impact

GPU firmware accepts input from the host without validating it, with outcomes up to code execution inside the firmware. NVIDIA assigned two ids for the same flaw class in the same component with the same score and fix - CVE-2026-47546 and CVE-2026-47547 in bulletin 2026/5861 - and an operator takes one action for both. As with the other firmware items here, the exposure is below the host OS, so a host rebuild does not clear it; and the record does not state how the fixed firmware reaches the card.

Who can reach it

Local attacker with high privileges on the GPU node, Windows or Linux.

What to do

Apply the fix in NVIDIA bulletin 2026/5861 for your GPU and driver branch; one update covers both ids. Confirm in the bulletin whether the firmware ships with the driver or as a separate image, and take the node out of service for the update.

Also covers 1 CVE

The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.

CVE-2026-47547

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.