GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA GPU driver: use-after-free in the kernel module, scored as requiring physical access

CVSS 6.4CVE-2026-47586NVIDIA / GPU stackcurated

Impact

A use-after-free in the GPU driver kernel module with code execution, privilege escalation, information disclosure, data tampering and denial of service listed. NVIDIA scored it AV:P with no privileges required, meaning the trigger needs physical access to the machine rather than a tenant workload - in a datacenter that is cage access or a maintenance hand, not a remote attacker. Worth patching on the regular driver cycle; not a reason to open a window tonight unless your threat model includes people at the rack.

Who can reach it

Physical access to the host (AV:P), no authentication required, high attack complexity.

What to do

Update the GPU display driver to the fixed branch in NVIDIA bulletin 2026/5861 on your normal driver cycle. The update requires a node drain and reboot to swap the kernel module.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.