GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA GPU driver for Linux: race condition in the kernel mode layer leads to an out-of-bounds write

CVSS 6.4CVE-2026-47565NVIDIA / GPU stackcurated

Impact

A privileged local user can win a race in the kernel mode layer and get an out-of-bounds write, with code execution and privilege escalation listed. Both high privileges and high attack complexity are required, so this is one of the lower-priority items in bulletin 5861 for most fleets - it buys a host-kernel foothold to someone who is already privileged on the node. The guest driver is in the affected list, so Linux VMs with passthrough or vGPU devices are covered too.

Who can reach it

Local attacker with high privileges on the Linux GPU node or guest; a race must be won (AC:H).

What to do

Update the Linux GPU display driver and guest driver to the fixed branch in NVIDIA bulletin 2026/5861. Drain the node and reboot. Safe to fold into the same maintenance window as the rest of the bulletin.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.