GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA GPU driver for Windows: out-of-bounds write in the kernel module leads to code execution

CVSS 7.0CVE-2026-47582NVIDIA / GPU stackcurated

Impact

An out-of-bounds write in the Windows kernel module gives a local attacker the full set of outcomes NVIDIA enumerates: code execution, privilege escalation, information disclosure, data tampering and denial of service. Attack complexity is rated high, so this is not a drive-by, but kernel code execution on a GPU host is a tenant-to-host escape wherever untrusted code runs on the node. The affected list covers the guest driver and the Virtual GPU Manager, so Windows vGPU guests matter here too.

Who can reach it

Local low-privileged user on a Windows host with the NVIDIA driver loaded, including inside a Windows vGPU guest. High attack complexity.

What to do

Install the fixed Windows driver branch from NVIDIA bulletin 2026/5861, and the fixed vGPU manager where vGPU is in use. Reboot each host after the driver update; vGPU hosts need their guests evacuated first.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.