GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA Windows GPU driver: integer overflow in the DIAG escape handler causes an out-of-bounds write

CVSS 7.8CVE-2026-47575NVIDIA / GPU stackcurated

Impact

The diagnostic escape handler overflows a size calculation and writes out of bounds in kernel memory, triggered by a local unprivileged user. The named handler makes this more actionable than the generic entries in the same bulletin: the DIAG escape interface is a specific, reachable entry point rather than an unspecified code path. NVIDIA lists denial of service and code execution, so on a Windows GPU instance expect both a reliable crash primitive and an escalation candidate.

Who can reach it

Local, unprivileged. Any user process on an affected Windows system able to issue a DIAG escape to the driver.

What to do

Install the Windows driver branch from NVIDIA bulletin 2026/5861; the record names no fixed version. Reboot the instance to complete the update, which means draining it first.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.