GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA NVAPI on Windows: out-of-bounds write reachable by a local attacker

CVSS 7.8CVE-2026-47573NVIDIA / GPU stackcurated

Impact

NVAPI is the user-facing control library applications use to query and configure NVIDIA GPUs on Windows, and it contains an out-of-bounds write. An attacker who can get a privileged process to call through NVAPI with controlled input, or who exploits it within their own session, gains code execution in that process's context. On Windows GPU instances NVAPI is pulled in by management agents and monitoring tooling, which is where the privilege is.

Who can reach it

Local. A user on an affected Windows host or guest that has the NVIDIA driver and NVAPI installed.

What to do

Apply the Windows driver package from NVIDIA bulletin 2026/5861, which ships NVAPI; no fixed version appears in this record. The update requires a reboot of the instance, so drain Windows GPU VMs before applying.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.