NVIDIA Windows GPU driver: integer underflow in the kernel module
CVSS 7.8CVE-2026-47585NVIDIA / GPU stackcurated
Impact
A subtraction underflows in the Windows kernel module, producing a huge unsigned length from what should have been a small value. Code that then uses that length as a bound reads or writes far outside its buffer. A local user drives it, and the driver's SYSTEM context means the payoff is full control of the Windows GPU instance.
Who can reach it
Local. A user process on an affected Windows host or guest.
What to do
Install the Windows driver update from NVIDIA bulletin 2026/5861; no fixed version is stated in this record. Reboot after updating, so drain the instance first.
References
Related entries
- NVIDIA Linux GPU driver: incorrect authorization lets an unprivileged user write read-only memoryCVE-2026-47591 · NVIDIA GPU Display Driver for Linux (kernel mode layer, read-only memory authorization)High
- NVIDIA Windows GPU driver: unprivileged user causes an out-of-bounds write in the kernel mode layerCVE-2026-47593 · NVIDIA GPU Display Driver for Windows (kernel mode layer)High
- NVIDIA open GPU kernel module: missing self-reference guard in map cleanup gives a use-after-freeCVE-2026-47597 · NVIDIA open GPU kernel module (Resource Server, map cleanup path)High
- NVIDIA open GPU kernel module: memory access permissions are lost during DMA mappingCVE-2026-47599 · NVIDIA open GPU kernel module for Linux (DMA mapping path)High
- NVIDIA GPU driver: error-handling path operates on an improperly initialized resourceCVE-2026-47600 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer, error handling)High
- NVIDIA open GPU kernel module: read-only DMA-BUF imported from another device becomes writableCVE-2026-47601 · NVIDIA open GPU kernel module (DMA-BUF import path)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.