NVIDIA Windows GPU driver: type confusion in the kernel module
Impact
The kernel module can be made to treat an object as the wrong type, so fields are interpreted against the wrong layout. Type confusion typically yields a write primitive because a pointer field in one structure lines up with a data field in another. The trigger is local on an affected Windows host or guest, and the driver runs at SYSTEM.
Who can reach it
Local. A user process on an affected Windows system with the NVIDIA driver installed.
What to do
Update to the Windows driver branch named in NVIDIA bulletin 2026/5861; the record gives no fixed version. Drain and reboot the affected Windows GPU instance to complete the update.
References
Related entries
- NVIDIA Windows GPU driver: out-of-bounds read with no privileges required, leaking data and crashing the driverCVE-2026-47576 · NVIDIA GPU Display Driver for Windows (kernel module)High
- NVIDIA Windows GPU driver: incorrect comparison in the kernel moduleCVE-2026-47577 · NVIDIA GPU Display Driver for Windows (kernel module)High
- NVIDIA Windows GPU driver: integer underflow in the kernel moduleCVE-2026-47585 · NVIDIA GPU Display Driver for Windows (kernel module, size arithmetic)High
- NVIDIA Linux GPU driver: incorrect authorization lets an unprivileged user write read-only memoryCVE-2026-47591 · NVIDIA GPU Display Driver for Linux (kernel mode layer, read-only memory authorization)High
- NVIDIA Windows GPU driver: unprivileged user causes an out-of-bounds write in the kernel mode layerCVE-2026-47593 · NVIDIA GPU Display Driver for Windows (kernel mode layer)High
- NVIDIA open GPU kernel module: missing self-reference guard in map cleanup gives a use-after-freeCVE-2026-47597 · NVIDIA open GPU kernel module (Resource Server, map cleanup path)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.