NVIDIA GPU driver: a user can access memory belonging to another user's process
Impact
This is the one in the bulletin that breaks tenant isolation directly rather than as a second-order effect of memory corruption: the kernel mode layer lets one user reach another user's process memory. On a node where several customers share a GPU, or where MIG slices and separate pods sit on the same board, that is a read of someone else's model weights, prompts or training data with no escalation step in between. It is also the hardest kind of incident to detect after the fact, since nothing crashes.
Who can reach it
Local, unprivileged. Any tenant with a GPU pod on the same node as the victim, or any local user with the NVIDIA device nodes; no authentication.
What to do
Apply the driver branch update from NVIDIA bulletin 2026/5861; the record gives no fixed version. Drain and reboot each shared GPU node. Until the fix is in, treat co-tenancy on affected nodes as the real risk and consider giving sensitive workloads dedicated nodes rather than shared boards.
References
Related entries
- NVIDIA Linux GPU driver: unprivileged user triggers use-after-free in the kernel moduleCVE-2026-47560 · NVIDIA GPU Display Driver for Linux (kernel mode layer, object lifetime)High
- NVIDIA Linux GPU driver: ioctl input buffer size is unvalidated, giving a kernel out-of-bounds writeCVE-2026-47561 · NVIDIA GPU Display Driver for Linux (kernel mode layer, ioctl input buffer validation)High
- NVIDIA Linux GPU driver: user-triggerable NULL pointer dereference in the kernel moduleCVE-2026-47563 · NVIDIA GPU Display Driver for Linux (kernel mode layer)High
- NVIDIA Linux GPU driver: handle recycle race causes type confusion in the kernel moduleCVE-2026-47569 · NVIDIA GPU Display Driver for Linux (kernel mode layer, object handle allocator)High
- NVIDIA CUDA driver on Windows: library loaded from an uncontrolled search pathCVE-2026-47570 · NVIDIA CUDA driver for Windows (library search path)High
- NVIDIA Windows GPU driver: escape handler authorization check based on client context can be bypassedCVE-2026-47571 · NVIDIA GPU Display Driver for Windows (kernel-mode escape handling, authorization check)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.