NVIDIA Windows GPU driver: integer overflow in the DIAG escape handler causes an out-of-bounds write
Impact
The diagnostic escape handler overflows a size calculation and writes out of bounds in kernel memory, triggered by a local unprivileged user. The named handler makes this more actionable than the generic entries in the same bulletin: the DIAG escape interface is a specific, reachable entry point rather than an unspecified code path. NVIDIA lists denial of service and code execution, so on a Windows GPU instance expect both a reliable crash primitive and an escalation candidate.
Who can reach it
Local, unprivileged. Any user process on an affected Windows system able to issue a DIAG escape to the driver.
What to do
Install the Windows driver branch from NVIDIA bulletin 2026/5861; the record names no fixed version. Reboot the instance to complete the update, which means draining it first.
References
Related entries
- NVIDIA Windows GPU driver: incorrect comparison in the kernel moduleCVE-2026-47577 · NVIDIA GPU Display Driver for Windows (kernel module)High
- NVIDIA Windows GPU driver: incorrect buffer size calculation in the kernel mode layerCVE-2026-47578 · NVIDIA GPU Display Driver for Windows (kernel mode layer, buffer size calculation)High
- NVIDIA Windows GPU driver: use-after-free with a scope-changing impact beyond the vulnerable componentCVE-2026-47579 · NVIDIA GPU Display Driver for Windows (kernel mode driver)High
- NVIDIA Windows GPU driver: type confusion in the kernel moduleCVE-2026-47583 · NVIDIA GPU Display Driver for Windows (kernel module)High
- NVIDIA Windows GPU driver: integer underflow in the kernel moduleCVE-2026-47585 · NVIDIA GPU Display Driver for Windows (kernel module, size arithmetic)High
- NVIDIA Linux GPU driver: incorrect authorization lets an unprivileged user write read-only memoryCVE-2026-47591 · NVIDIA GPU Display Driver for Linux (kernel mode layer, read-only memory authorization)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.