NVIDIA Windows GPU driver: escape handler authorization check based on client context can be bypassed
Impact
The driver restricts certain escape operations based on the calling client's execution context, and that check can be bypassed by a local attacker. The result is that operations meant for privileged or internal callers become available to any user process. Escapes are a broad interface, so this effectively widens the attack surface of the whole driver rather than exposing one function, and it is the kind of bypass that makes other hardened paths reachable again.
Who can reach it
Local. Any user process on an affected Windows host or guest that can issue driver escapes.
What to do
Install the Windows driver update from NVIDIA bulletin 2026/5861; the record does not state a fixed version. Reboot after updating; drain the instance first. Guest driver and Virtual GPU Manager installs are listed as affected.
References
Related entries
- NVIDIA Linux GPU driver: type confusion in the kernel mode layerCVE-2026-47572 · NVIDIA GPU Display Driver for Linux (kernel mode layer)High
- NVIDIA NVAPI on Windows: out-of-bounds write reachable by a local attackerCVE-2026-47573 · NVIDIA NVAPI for WindowsHigh
- NVIDIA vGPU Manager on Linux: incorrect resource transfer across isolation boundariesCVE-2026-47574 · NVIDIA vGPU Virtual GPU Manager for Linux (resource transfer across isolation spheres)High
- NVIDIA Windows GPU driver: integer overflow in the DIAG escape handler causes an out-of-bounds writeCVE-2026-47575 · NVIDIA GPU Display Driver for Windows (DIAG escape handler)High
- NVIDIA Windows GPU driver: incorrect comparison in the kernel moduleCVE-2026-47577 · NVIDIA GPU Display Driver for Windows (kernel module)High
- NVIDIA Windows GPU driver: incorrect buffer size calculation in the kernel mode layerCVE-2026-47578 · NVIDIA GPU Display Driver for Windows (kernel mode layer, buffer size calculation)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.