NVIDIA Windows GPU driver: out-of-bounds read with no privileges required, leaking data and crashing the driver
Impact
This is the only item in bulletin 2026/5861 whose vector requires no privileges at all on the local system, where every other entry needs at least a low-privilege account. The outcome is information disclosure plus denial of service rather than code execution, so the practical risk is leaked kernel data and a GPU driver crash that takes the instance's workload with it. Rank it below the write primitives in the same bulletin, but note that the lower privilege bar means sandboxed or heavily restricted contexts on the host can still reach it.
Who can reach it
Local with no privileges required (AV:L/PR:N). A process on an affected Windows host or guest, including low-trust contexts.
What to do
Update the Windows driver per NVIDIA bulletin 2026/5861; no fixed version is given in this record. Reboot after the update; drain the affected Windows GPU instance first.
References
Related entries
- NVIDIA Windows GPU driver: incorrect comparison in the kernel moduleCVE-2026-47577 · NVIDIA GPU Display Driver for Windows (kernel module)High
- NVIDIA Windows GPU driver: type confusion in the kernel moduleCVE-2026-47583 · NVIDIA GPU Display Driver for Windows (kernel module)High
- Linux amdgpu: unbounded FRU PIA TLV walk reads out of bounds on malformed EEPROM dataCVE-2026-97428 · Linux kernel drm/amdgpu (FRU EEPROM PIA/TLV parser)High
- DGX H100 BMC (IPMI): Credential exposureCVE-2023-25531 · DGX H100 BMC (IPMI)High
- NVIDIA License System - Delegated Licensing Service (DLS): An unauthorised action against the DLS reaches partialCVE-2024-0122 · NVIDIA License System - Delegated Licensing Service (DLS)High
- Container Toolkit / GPU Operator: Container escape to host root (insufficient input validation)CVE-2024-0135 · Container Toolkit / GPU OperatorHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.