GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA CUDA driver on Windows: library loaded from an uncontrolled search path

CVSS 7.8CVE-2026-47570NVIDIA / GPU stackcurated

Impact

The CUDA driver loads a library without pinning where it comes from, so an attacker who can place a DLL on the search path gets their code executed in the context of whatever loads CUDA. On Windows GPU instances that often means a service running with high privilege, and it also gives a quiet persistence foothold that survives restarts of the application. Shared build agents and rendering workers where several users can write to common directories are the realistic setting for this.

Who can reach it

Local. A user who can write a file into a directory on the library search path used by a CUDA process on an affected Windows system.

What to do

Update the Windows driver per NVIDIA bulletin 2026/5861; no fixed version is listed in this record. As a hardening step independent of the patch, audit write permissions on directories that CUDA processes search and on the working directories of GPU services. Applying the driver update requires a reboot of the instance.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.