GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA Linux GPU driver: ioctl input buffer size is unvalidated, giving a kernel out-of-bounds write

CVSS 7.8CVE-2026-47561NVIDIA / GPU stackcurated

Impact

The driver trusts the size of an ioctl input buffer supplied by the caller and writes past the allocation in kernel memory. This is the cleanest primitive in the bulletin: a single ioctl from an unprivileged process, with caller-controlled length, against host kernel memory. Any tenant whose pod has the GPU device nodes can reach it, and the GPU driver is privileged enough that a successful write means host root.

Who can reach it

Local, unprivileged. One ioctl on /dev/nvidiactl or a per-device node; no authentication beyond process access to the device.

What to do

Install the fixed driver branch from NVIDIA bulletin 2026/5861 (versions are in the bulletin, not in this record). Drain each GPU node and reboot so the new kernel module is in place; Virtual GPU Manager hosts and guest driver images need the same update.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.