NVIDIA Linux GPU driver: type confusion in the kernel mode layer
Impact
A local user can make the kernel mode layer treat an object as the wrong type. The advisory text gives no further detail, so take it at face value: a memory-safety flaw in the privileged GPU driver reachable from an ordinary user context, with code execution and privilege escalation listed as possible outcomes. On a shared GPU node that is a tenant-to-host boundary crossing.
Who can reach it
Local, unprivileged. A user or container with access to the NVIDIA device nodes; no authentication.
What to do
Install the driver branch from NVIDIA bulletin 2026/5861; the record does not state fixed versions. Drain the GPU node and reboot to load the new kernel module.
References
Related entries
- NVIDIA Linux GPU driver: user-triggerable NULL pointer dereference in the kernel moduleCVE-2026-47563 · NVIDIA GPU Display Driver for Linux (kernel mode layer)High
- NVIDIA NVAPI on Windows: out-of-bounds write reachable by a local attackerCVE-2026-47573 · NVIDIA NVAPI for WindowsHigh
- NVIDIA vGPU Manager on Linux: incorrect resource transfer across isolation boundariesCVE-2026-47574 · NVIDIA vGPU Virtual GPU Manager for Linux (resource transfer across isolation spheres)High
- NVIDIA Windows GPU driver: integer overflow in the DIAG escape handler causes an out-of-bounds writeCVE-2026-47575 · NVIDIA GPU Display Driver for Windows (DIAG escape handler)High
- NVIDIA Windows GPU driver: incorrect comparison in the kernel moduleCVE-2026-47577 · NVIDIA GPU Display Driver for Windows (kernel module)High
- NVIDIA Windows GPU driver: incorrect buffer size calculation in the kernel mode layerCVE-2026-47578 · NVIDIA GPU Display Driver for Windows (kernel mode layer, buffer size calculation)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.