NVIDIA GPU driver for Linux: race condition in the kernel mode layer leads to an out-of-bounds write
Impact
A privileged local user can win a race in the kernel mode layer and get an out-of-bounds write, with code execution and privilege escalation listed. Both high privileges and high attack complexity are required, so this is one of the lower-priority items in bulletin 5861 for most fleets - it buys a host-kernel foothold to someone who is already privileged on the node. The guest driver is in the affected list, so Linux VMs with passthrough or vGPU devices are covered too.
Who can reach it
Local attacker with high privileges on the Linux GPU node or guest; a race must be won (AC:H).
What to do
Update the Linux GPU display driver and guest driver to the fixed branch in NVIDIA bulletin 2026/5861. Drain the node and reboot. Safe to fold into the same maintenance window as the rest of the bulletin.
References
Related entries
- NVIDIA GPU driver: use-after-free in the kernel module, scored as requiring physical accessCVE-2026-47586 · NVIDIA GPU Display Driver kernel module (use-after-free)Medium
- NVIDIA vGPU Manager (vGPU plugin): Time-of-check to time-of-use on a shared resource between guest and host plugin. ACVE-2020-5969 · NVIDIA vGPU Manager (vGPU plugin)Medium
- NVIDIA vGPU Manager (vGPU plugin): The plugin keeps using a resource it validated after the guest has changed it - aCVE-2021-1061 · NVIDIA vGPU Manager (vGPU plugin)Medium
- NVIDIA DCGM - nv-hostengine: A network-reachable caller drives nv-hostengine into an unhandled error conditionCVE-2022-21820 · NVIDIA DCGM - nv-hostengineMedium
- vGPU Manager: Improper permission managementCVE-2024-0085 · vGPU ManagerMedium
- NVIDIA NeMo: SaveRestoreConnector extracts .tar archives unsafely, so a crafted archive writes files outsideCVE-2024-0129 · NVIDIA NeMoMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.