GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA Linux GPU driver: unrate-limited error path lets a local user flood the kernel log

CVSS 5.5CVE-2026-47568NVIDIA / GPU stackcurated

Impact

A local user can repeatedly call an interface whose error path emits log messages with no rate limiting, filling the kernel ring buffer and whatever collects it. The practical damage on a GPU node is operational: real driver faults scroll out of dmesg, journald and the log pipeline absorb the volume, and on nodes where logs land on the root filesystem the disk can fill. NVIDIA rates it 5.5 for availability only. Affected products include the Tesla datacenter branch plus the vGPU guest driver and Virtual GPU Manager, so a noisy tenant VM can bury the host's view of its own hardware.

Who can reach it

Local, authenticated: any tenant with a GPU pod or login that can reach the NVIDIA driver interfaces. No elevated privileges required.

What to do

Update the GPU driver to a fixed version per NVIDIA security bulletin 2026/5861; the record does not state fixed versions. The driver swap requires unloading the kernel modules, so drain and reboot each GPU node. In the interim, rate-limiting or capping the kernel log sink (journald storage limits, log rotation on the root filesystem) blunts the disk-fill consequence without fixing the flaw.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.