NVIDIA Linux GPU driver: user-triggerable NULL pointer dereference in the kernel module
Impact
A local user can drive the kernel module into dereferencing a NULL pointer. The realistic outcome is an oops that takes the GPU driver, and often the node, out of service; NVIDIA lists the broader impacts the whole bulletin shares, but the described mechanism is a dereference of an unmapped address. On a GPU fleet the cost is availability: a tenant can repeatedly knock out an expensive node and force a reboot, and in-flight training work on that host is lost.
Who can reach it
Local, unprivileged. Any tenant with a GPU pod or a local user with the NVIDIA device nodes open.
What to do
Update to the driver branch in NVIDIA bulletin 2026/5861; no fixed version is stated in this record. The change is in the kernel module, so plan a drain and reboot per node. Until then, treat repeated GPU driver oopses on a shared node as a possible tenant abuse signal rather than hardware flakiness.
References
Related entries
- NVIDIA Linux GPU driver: type confusion in the kernel mode layerCVE-2026-47572 · NVIDIA GPU Display Driver for Linux (kernel mode layer)High
- NVIDIA Linux GPU driver: handle recycle race causes type confusion in the kernel moduleCVE-2026-47569 · NVIDIA GPU Display Driver for Linux (kernel mode layer, object handle allocator)High
- NVIDIA CUDA driver on Windows: library loaded from an uncontrolled search pathCVE-2026-47570 · NVIDIA CUDA driver for Windows (library search path)High
- NVIDIA Windows GPU driver: escape handler authorization check based on client context can be bypassedCVE-2026-47571 · NVIDIA GPU Display Driver for Windows (kernel-mode escape handling, authorization check)High
- NVIDIA NVAPI on Windows: out-of-bounds write reachable by a local attackerCVE-2026-47573 · NVIDIA NVAPI for WindowsHigh
- NVIDIA vGPU Manager on Linux: incorrect resource transfer across isolation boundariesCVE-2026-47574 · NVIDIA vGPU Virtual GPU Manager for Linux (resource transfer across isolation spheres)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.