GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA Linux GPU driver: unprivileged user bypasses an authorization check and changes privileged settings

CVSS 7.8CVE-2026-47552NVIDIA / GPU stackcurated

Impact

An authorization check meant to restrict privileged configuration can be bypassed, so an unprivileged local user changes driver settings that should require root. On a shared fleet that is a tenant reaching controls the operator owns: clocks, persistence and similar node-wide state that affects every other workload on the board. NVIDIA also rates the outcome as reaching code execution, so treat this as more than a configuration nuisance.

Who can reach it

Local, unprivileged. Any tenant with a GPU pod or a local user with the device nodes; no credentials required.

What to do

Update the driver to the branch given in NVIDIA bulletin 2026/5861; the record does not list a fixed version. Drain and reboot each GPU node, including Virtual GPU Manager hosts, to load the fixed module.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.