NVIDIA Linux GPU driver: ioctl input buffer size is unvalidated, giving a kernel out-of-bounds write
Impact
The driver trusts the size of an ioctl input buffer supplied by the caller and writes past the allocation in kernel memory. This is the cleanest primitive in the bulletin: a single ioctl from an unprivileged process, with caller-controlled length, against host kernel memory. Any tenant whose pod has the GPU device nodes can reach it, and the GPU driver is privileged enough that a successful write means host root.
Who can reach it
Local, unprivileged. One ioctl on /dev/nvidiactl or a per-device node; no authentication beyond process access to the device.
What to do
Install the fixed driver branch from NVIDIA bulletin 2026/5861 (versions are in the bulletin, not in this record). Drain each GPU node and reboot so the new kernel module is in place; Virtual GPU Manager hosts and guest driver images need the same update.
References
Related entries
- NVIDIA Linux GPU driver: user-triggerable NULL pointer dereference in the kernel moduleCVE-2026-47563 · NVIDIA GPU Display Driver for Linux (kernel mode layer)High
- NVIDIA Linux GPU driver: handle recycle race causes type confusion in the kernel moduleCVE-2026-47569 · NVIDIA GPU Display Driver for Linux (kernel mode layer, object handle allocator)High
- NVIDIA CUDA driver on Windows: library loaded from an uncontrolled search pathCVE-2026-47570 · NVIDIA CUDA driver for Windows (library search path)High
- NVIDIA Windows GPU driver: escape handler authorization check based on client context can be bypassedCVE-2026-47571 · NVIDIA GPU Display Driver for Windows (kernel-mode escape handling, authorization check)High
- NVIDIA Linux GPU driver: type confusion in the kernel mode layerCVE-2026-47572 · NVIDIA GPU Display Driver for Linux (kernel mode layer)High
- NVIDIA NVAPI on Windows: out-of-bounds write reachable by a local attackerCVE-2026-47573 · NVIDIA NVAPI for WindowsHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.