GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA Windows GPU driver: incorrect buffer size calculation in the kernel mode layer

CVSS 7.8CVE-2026-47578NVIDIA / GPU stackcurated

Impact

The driver computes a buffer size incorrectly, so the allocation does not match what is later written into or read from it. The result is the usual overflow or over-read in kernel memory, triggered by a local attacker. On Windows GPU instances the kernel mode driver runs at SYSTEM, so a successful overflow ends the privilege question for that host or guest.

Who can reach it

Local. Any user process on an affected Windows system able to call the driver.

What to do

Apply the Windows driver branch from NVIDIA bulletin 2026/5861; no fixed version appears in this record. Reboot each updated instance; Virtual GPU Manager is also listed among affected products and needs its own maintenance window.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.