GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA Linux GPU driver: unprivileged user triggers use-after-free in the kernel module

CVSS 7.8CVE-2026-47560NVIDIA / GPU stack+2 more CVEscurated

Impact

An unprivileged local user can free an object the driver still references and then have the kernel use it, in one case simply by issuing a particular sequence of driver commands. NVIDIA assigned three ids in bulletin 2026/5861 for this same class on the Linux driver (CVE-2026-47560, CVE-2026-47587, CVE-2026-47588) with identical scores and one driver update; the records give no distinguishing detail beyond the trigger being ordinary driver calls. Use-after-free in a privileged kernel module is the standard route from a tenant container to host root on a GPU node.

Who can reach it

Local, unprivileged. Any tenant with a GPU pod, or any local user with /dev/nvidia* open. No authentication beyond that.

What to do

Update to the driver branch listed in NVIDIA bulletin 2026/5861; fixed versions are in the bulletin, not in this record. All three ids are closed by that one update. Drain and reboot each GPU node; the guest driver inside vGPU VMs needs the same update.

Also covers 2 CVEs

The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.

CVE-2026-47587CVE-2026-47588

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.