GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA GPU driver for Windows: missing authorization in the kernel module allows cross-scope information disclosure

CVSS 7.3CVE-2026-47580NVIDIA / GPU stackcurated

Impact

A local user on a Windows GPU node can reach a kernel module path that fails to check authorization, yielding information disclosure and data tampering. The CVSS vector has a changed scope (S:C) with high confidentiality impact, which means the data obtained is outside the attacker's own security boundary - on a shared Windows GPU host that can mean another session's data. Relevant to operators running Tesla-class cards under Windows Server for rendering or inference; Linux fleets are unaffected by this id.

Who can reach it

Local authenticated user with low privileges on a Windows host that has the NVIDIA display driver loaded.

What to do

Update the Windows GPU display driver to the fixed branch listed in NVIDIA bulletin 2026/5861. A driver update on Windows requires a reboot, so plan a node drain and reboot per host.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.