NVIDIA GPU driver for Linux: signature verification can be bypassed under memory pressure
Impact
The kernel mode layer verifies cryptographic signatures improperly, and under memory pressure the verification can be bypassed entirely. On a GPU node that is deliberately kept near its memory ceiling - which is normal for training and inference workloads - an unprivileged local user can push the driver into the failing path and tamper with content that is supposed to be signature-checked, or crash the driver. NVIDIA lists denial of service and data tampering, not code execution, but a verification step that fails open is worth treating as an integrity control you no longer have.
Who can reach it
Local unprivileged user on the GPU node, for example any tenant with a GPU pod or container that can allocate memory and talk to the driver. No special privileges required.
What to do
Update the Linux GPU display driver to the fixed branch in NVIDIA bulletin 2026/5861. Replacing the driver means unloading the kernel modules, which cannot be done while GPUs are in use - drain the node and reboot. No vendor-documented mitigation short of patching.
References
Related entries
- NVIDIA GPU driver: local user can make the kernel mode driver dereference an untrusted pointerCVE-2026-47602 · NVIDIA GPU Display Driver kernel mode driver (untrusted pointer dereference)High
- Linux kernel amdgpu display core (DC/DM) (drm/amd/display): An out-of-bounds access in the amdgpu display core (DC/DM)CVE-2026-53138 · Linux kernel amdgpu display core (DC/DM) (drm/amd/display)High
- Linux kernel amdgpu display core (DC/DM) (drm/amd/display): An out-of-bounds access in the amdgpu display core (DC/DM)CVE-2026-53330 · Linux kernel amdgpu display core (DC/DM) (drm/amd/display)High
- Linux kernel amdgpu user-mode queues (doorbell submission path) (drm/amdgpu): A correctness defect in the amdgpuCVE-2026-68103 · Linux kernel amdgpu user-mode queues (doorbell submission path) (drm/amdgpu)High
- NVIDIA/Mellanox ConnectX driver (mlx5_ib DEVX subscribe-event unwind): DEVX is the raw device-command escape hatch thatCVE-2026-74395 · NVIDIA/Mellanox ConnectX driver (mlx5_ib DEVX subscribe-event unwind)High
- Linux amdgpu VCN: integer overflow in dec_msg buffer count lets the parser run past the message BOCVE-2026-89818 · Linux kernel drm/amdgpu VCN decode message parser (num_buffers bounds check)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.