NVIDIA Linux GPU driver: handle recycle race causes type confusion in the kernel module
Impact
A race in how object handles are recycled lets a local user get a handle resolved to an object of a different type, so the kernel operates on a structure that is not what the code expects. Type confusion of this kind usually converts into a controlled write. Being a race, it is probabilistic, but a tenant on a multi-core GPU node can retry cheaply and without detection.
Who can reach it
Local, unprivileged, with concurrency. Any tenant process or container holding the NVIDIA device nodes.
What to do
Apply the driver update named in NVIDIA bulletin 2026/5861; the record gives no fixed version. Drain and reboot each GPU node to load the fixed kernel module.
References
Related entries
- NVIDIA CUDA driver on Windows: library loaded from an uncontrolled search pathCVE-2026-47570 · NVIDIA CUDA driver for Windows (library search path)High
- NVIDIA Windows GPU driver: escape handler authorization check based on client context can be bypassedCVE-2026-47571 · NVIDIA GPU Display Driver for Windows (kernel-mode escape handling, authorization check)High
- NVIDIA Linux GPU driver: type confusion in the kernel mode layerCVE-2026-47572 · NVIDIA GPU Display Driver for Linux (kernel mode layer)High
- NVIDIA NVAPI on Windows: out-of-bounds write reachable by a local attackerCVE-2026-47573 · NVIDIA NVAPI for WindowsHigh
- NVIDIA vGPU Manager on Linux: incorrect resource transfer across isolation boundariesCVE-2026-47574 · NVIDIA vGPU Virtual GPU Manager for Linux (resource transfer across isolation spheres)High
- NVIDIA Windows GPU driver: integer overflow in the DIAG escape handler causes an out-of-bounds writeCVE-2026-47575 · NVIDIA GPU Display Driver for Windows (DIAG escape handler)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.