GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA Linux GPU driver: incorrect authorization lets an unprivileged user write read-only memory

CVSS 7.8CVE-2026-47591NVIDIA / GPU stackcurated

Impact

The kernel mode layer performs the wrong authorization check before granting write access, so an unprivileged local user can obtain write access to memory marked read-only. Unlike the permission-preservation bugs in the same bulletin, the root cause here is a missing check rather than lost metadata, so a mitigation that depends on how buffers are mapped will not help. On a multi-tenant GPU node, a single container that can reach the driver can corrupt kernel-visible state and escalate off the node.

Who can reach it

Local, unprivileged. Any tenant with a GPU pod or any local user who can open the NVIDIA device nodes. No authentication step beyond that.

What to do

Apply the driver update from NVIDIA bulletin 2026/5861; fixed versions are in the bulletin, not in this record. The kernel module must be replaced, so drain and reboot each affected GPU node. Virtual GPU Manager hosts are also listed as affected and need the same maintenance window.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.