GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA GPU driver for Linux: signature verification can be bypassed under memory pressure

CVSS 7.1CVE-2026-47554NVIDIA / GPU stackcurated

Impact

The kernel mode layer verifies cryptographic signatures improperly, and under memory pressure the verification can be bypassed entirely. On a GPU node that is deliberately kept near its memory ceiling - which is normal for training and inference workloads - an unprivileged local user can push the driver into the failing path and tamper with content that is supposed to be signature-checked, or crash the driver. NVIDIA lists denial of service and data tampering, not code execution, but a verification step that fails open is worth treating as an integrity control you no longer have.

Who can reach it

Local unprivileged user on the GPU node, for example any tenant with a GPU pod or container that can allocate memory and talk to the driver. No special privileges required.

What to do

Update the Linux GPU display driver to the fixed branch in NVIDIA bulletin 2026/5861. Replacing the driver means unloading the kernel modules, which cannot be done while GPUs are in use - drain the node and reboot. No vendor-documented mitigation short of patching.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.