GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA Windows GPU driver: use-after-free with a scope-changing impact beyond the vulnerable component

CVSS 7.8CVE-2026-47579NVIDIA / GPU stackcurated

Impact

A local user can trigger a use-after-free in the Windows kernel mode driver. This one carries a different CVSS vector from the rest of the bulletin: high attack complexity but a changed scope, meaning successful exploitation affects resources beyond the driver itself. On a virtualized GPU host that is the shape of a guest-to-host or cross-boundary impact, so do not lump it in with the ordinary in-guest escalations even though the score matches.

Who can reach it

Local, low privilege, high attack complexity. A user on an affected Windows system; the guest driver is listed among affected products.

What to do

Apply the Windows driver update from NVIDIA bulletin 2026/5861; no fixed version is stated here. Reboot each updated Windows host or guest, which means draining the instance first.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.