GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA Windows GPU driver: untrusted user pointer is dereferenced without validation

CVSS 7.8CVE-2026-47550NVIDIA / GPU stackcurated

Impact

The kernel mode driver takes a pointer supplied by an unprivileged user and dereferences it without checking it. That is a textbook arbitrary read or write primitive: the attacker chooses the address the kernel touches, so exploitation tends to be reliable rather than probabilistic. Treat this as the highest-confidence escalation in the Windows half of bulletin 2026/5861 for any Windows GPU instances you operate.

Who can reach it

Local, unprivileged. Any user able to issue driver calls on an affected Windows host or guest.

What to do

Install the Windows driver branch from NVIDIA bulletin 2026/5861; the record gives no fixed version. Reboot the instance after updating, so drain affected Windows GPU VMs and hosts first. Virtual GPU Manager is also listed among affected products.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.