GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA Windows GPU driver: out-of-bounds read with no privileges required, leaking data and crashing the driver

CVSS 7.7CVE-2026-47576NVIDIA / GPU stackcurated

Impact

This is the only item in bulletin 2026/5861 whose vector requires no privileges at all on the local system, where every other entry needs at least a low-privilege account. The outcome is information disclosure plus denial of service rather than code execution, so the practical risk is leaked kernel data and a GPU driver crash that takes the instance's workload with it. Rank it below the write primitives in the same bulletin, but note that the lower privilege bar means sandboxed or heavily restricted contexts on the host can still reach it.

Who can reach it

Local with no privileges required (AV:L/PR:N). A process on an affected Windows host or guest, including low-trust contexts.

What to do

Update the Windows driver per NVIDIA bulletin 2026/5861; no fixed version is given in this record. Reboot after the update; drain the affected Windows GPU instance first.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.