NVIDIA Linux GPU driver: unprivileged user bypasses an authorization check and changes privileged settings
Impact
An authorization check meant to restrict privileged configuration can be bypassed, so an unprivileged local user changes driver settings that should require root. On a shared fleet that is a tenant reaching controls the operator owns: clocks, persistence and similar node-wide state that affects every other workload on the board. NVIDIA also rates the outcome as reaching code execution, so treat this as more than a configuration nuisance.
Who can reach it
Local, unprivileged. Any tenant with a GPU pod or a local user with the device nodes; no credentials required.
What to do
Update the driver to the branch given in NVIDIA bulletin 2026/5861; the record does not list a fixed version. Drain and reboot each GPU node, including Virtual GPU Manager hosts, to load the fixed module.
References
Related entries
- NVIDIA Linux GPU driver: double-free of imported memory state in the kernel moduleCVE-2026-47558 · NVIDIA GPU Display Driver for Linux (kernel mode layer, imported memory state)High
- NVIDIA GPU driver: a user can access memory belonging to another user's processCVE-2026-47559 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer, process memory isolation)High
- NVIDIA Linux GPU driver: unprivileged user triggers use-after-free in the kernel moduleCVE-2026-47560 · NVIDIA GPU Display Driver for Linux (kernel mode layer, object lifetime)High
- NVIDIA Linux GPU driver: ioctl input buffer size is unvalidated, giving a kernel out-of-bounds writeCVE-2026-47561 · NVIDIA GPU Display Driver for Linux (kernel mode layer, ioctl input buffer validation)High
- NVIDIA Linux GPU driver: user-triggerable NULL pointer dereference in the kernel moduleCVE-2026-47563 · NVIDIA GPU Display Driver for Linux (kernel mode layer)High
- NVIDIA Linux GPU driver: handle recycle race causes type confusion in the kernel moduleCVE-2026-47569 · NVIDIA GPU Display Driver for Linux (kernel mode layer, object handle allocator)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.