GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA GPU driver: a user can access memory belonging to another user's process

CVSS 7.8CVE-2026-47559NVIDIA / GPU stackcurated

Impact

This is the one in the bulletin that breaks tenant isolation directly rather than as a second-order effect of memory corruption: the kernel mode layer lets one user reach another user's process memory. On a node where several customers share a GPU, or where MIG slices and separate pods sit on the same board, that is a read of someone else's model weights, prompts or training data with no escalation step in between. It is also the hardest kind of incident to detect after the fact, since nothing crashes.

Who can reach it

Local, unprivileged. Any tenant with a GPU pod on the same node as the victim, or any local user with the NVIDIA device nodes; no authentication.

What to do

Apply the driver branch update from NVIDIA bulletin 2026/5861; the record gives no fixed version. Drain and reboot each shared GPU node. Until the fix is in, treat co-tenancy on affected nodes as the real risk and consider giving sensitive workloads dedicated nodes rather than shared boards.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.