GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA Linux GPU driver: double-free of imported memory state in the kernel module

CVSS 7.8CVE-2026-47558NVIDIA / GPU stackcurated

Impact

State tracking imported memory can be freed twice, corrupting the kernel allocator in a way that an unprivileged local user can steer. Memory import is how buffers move between processes and devices on a GPU node, so the path is routine traffic for frameworks rather than an exotic call. Successful exploitation gives host-level code execution from a tenant context.

Who can reach it

Local, unprivileged. A tenant container or user with access to the NVIDIA device nodes.

What to do

Apply the driver update referenced in NVIDIA bulletin 2026/5861; no fixed version is given here. Drain the node, reload or reinstall the kernel module, and reboot to be sure no stale module remains.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.