NVIDIA Linux GPU driver: unprivileged user triggers use-after-free in the kernel module
Impact
An unprivileged local user can free an object the driver still references and then have the kernel use it, in one case simply by issuing a particular sequence of driver commands. NVIDIA assigned three ids in bulletin 2026/5861 for this same class on the Linux driver (CVE-2026-47560, CVE-2026-47587, CVE-2026-47588) with identical scores and one driver update; the records give no distinguishing detail beyond the trigger being ordinary driver calls. Use-after-free in a privileged kernel module is the standard route from a tenant container to host root on a GPU node.
Who can reach it
Local, unprivileged. Any tenant with a GPU pod, or any local user with /dev/nvidia* open. No authentication beyond that.
What to do
Update to the driver branch listed in NVIDIA bulletin 2026/5861; fixed versions are in the bulletin, not in this record. All three ids are closed by that one update. Drain and reboot each GPU node; the guest driver inside vGPU VMs needs the same update.
Also covers 2 CVEs
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- NVIDIA Linux GPU driver: ioctl input buffer size is unvalidated, giving a kernel out-of-bounds writeCVE-2026-47561 · NVIDIA GPU Display Driver for Linux (kernel mode layer, ioctl input buffer validation)High
- NVIDIA Linux GPU driver: user-triggerable NULL pointer dereference in the kernel moduleCVE-2026-47563 · NVIDIA GPU Display Driver for Linux (kernel mode layer)High
- NVIDIA Linux GPU driver: handle recycle race causes type confusion in the kernel moduleCVE-2026-47569 · NVIDIA GPU Display Driver for Linux (kernel mode layer, object handle allocator)High
- NVIDIA CUDA driver on Windows: library loaded from an uncontrolled search pathCVE-2026-47570 · NVIDIA CUDA driver for Windows (library search path)High
- NVIDIA Windows GPU driver: escape handler authorization check based on client context can be bypassedCVE-2026-47571 · NVIDIA GPU Display Driver for Windows (kernel-mode escape handling, authorization check)High
- NVIDIA Linux GPU driver: type confusion in the kernel mode layerCVE-2026-47572 · NVIDIA GPU Display Driver for Linux (kernel mode layer)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.