GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA Windows GPU driver: escape handler authorization check based on client context can be bypassed

CVSS 7.8CVE-2026-47571NVIDIA / GPU stackcurated

Impact

The driver restricts certain escape operations based on the calling client's execution context, and that check can be bypassed by a local attacker. The result is that operations meant for privileged or internal callers become available to any user process. Escapes are a broad interface, so this effectively widens the attack surface of the whole driver rather than exposing one function, and it is the kind of bypass that makes other hardened paths reachable again.

Who can reach it

Local. Any user process on an affected Windows host or guest that can issue driver escapes.

What to do

Install the Windows driver update from NVIDIA bulletin 2026/5861; the record does not state a fixed version. Reboot after updating; drain the instance first. Guest driver and Virtual GPU Manager installs are listed as affected.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.