NVIDIA GPU firmware: improper input validation reachable from a privileged local user
Impact
GPU firmware accepts input from the host without validating it, with outcomes up to code execution inside the firmware. NVIDIA assigned two ids for the same flaw class in the same component with the same score and fix - CVE-2026-47546 and CVE-2026-47547 in bulletin 2026/5861 - and an operator takes one action for both. As with the other firmware items here, the exposure is below the host OS, so a host rebuild does not clear it; and the record does not state how the fixed firmware reaches the card.
Who can reach it
Local attacker with high privileges on the GPU node, Windows or Linux.
What to do
Apply the fix in NVIDIA bulletin 2026/5861 for your GPU and driver branch; one update covers both ids. Confirm in the bulletin whether the firmware ships with the driver or as a separate image, and take the node out of service for the update.
Also covers 1 CVE
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- NVIDIA GPU Display Driver (Windows nvlddmkm.sys + Linux nvidia.ko): Improper access control in the kernel-mode layerCVE-2021-1076 · NVIDIA GPU Display Driver (Windows nvlddmkm.sys + Linux nvidia.ko)Medium
- NVIDIA GPU Display Driver (Windows nvlddmkm.sys + Linux nvidia.ko): Reference-count mishandling on a driver resourceCVE-2021-1077 · NVIDIA GPU Display Driver (Windows nvlddmkm.sys + Linux nvidia.ko)Medium
- GPU Display Driver: Local privesc (kernel buffer overflow)CVE-2023-0198 · GPU Display DriverMedium
- DGX H100 BMC (REST): Privesc via auth flawCVE-2023-31015 · DGX H100 BMC (REST)Medium
- DGX A100 SBIOS: Integer overflow in SBIOSCVE-2023-31034 · DGX A100 SBIOSMedium
- Linux kernel amdgpu power management (SMU/powerplay) (drm/amd): An out-of-bounds access in the amdgpu power managementCVE-2023-52819 · Linux kernel amdgpu power management (SMU/powerplay) (drm/amd)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.