GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA Linux GPU driver: unsanitized version string lets a local user inject text into the kernel log

CVSS 4.4CVE-2026-47562NVIDIA / GPU stackcurated

Impact

A version string supplied by a local user is written to the kernel log without sanitization, so an attacker can inject arbitrary text - including forged log lines - into dmesg. On a GPU fleet the consequence is log integrity: an operator or a detection pipeline reading kernel messages can be shown fabricated driver, Xid or reset events, which is enough to misdirect an incident or hide a real one. NVIDIA scores it 4.4 with low integrity and low availability impact and no confidentiality loss. The Tesla datacenter branch, the vGPU guest driver and the Virtual GPU Manager are all listed, so a tenant VM can pollute the host-visible log stream.

Who can reach it

Local, authenticated: a user able to load or interact with the driver interface that passes the version string. No admin privileges needed; no network path.

What to do

Update the GPU driver to a fixed version listed in NVIDIA security bulletin 2026/5861 - the record names no versions. Driver replacement means unloading the kernel modules, so drain and reboot each GPU node. Until then, treat kernel-log driver lines as untrusted input in any alerting or forensic tooling that parses dmesg.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.