NVIDIA Linux GPU driver: incorrect authorization lets an unprivileged user write read-only memory
Impact
The kernel mode layer performs the wrong authorization check before granting write access, so an unprivileged local user can obtain write access to memory marked read-only. Unlike the permission-preservation bugs in the same bulletin, the root cause here is a missing check rather than lost metadata, so a mitigation that depends on how buffers are mapped will not help. On a multi-tenant GPU node, a single container that can reach the driver can corrupt kernel-visible state and escalate off the node.
Who can reach it
Local, unprivileged. Any tenant with a GPU pod or any local user who can open the NVIDIA device nodes. No authentication step beyond that.
What to do
Apply the driver update from NVIDIA bulletin 2026/5861; fixed versions are in the bulletin, not in this record. The kernel module must be replaced, so drain and reboot each affected GPU node. Virtual GPU Manager hosts are also listed as affected and need the same maintenance window.
References
Related entries
- NVIDIA Windows GPU driver: unprivileged user causes an out-of-bounds write in the kernel mode layerCVE-2026-47593 · NVIDIA GPU Display Driver for Windows (kernel mode layer)High
- NVIDIA open GPU kernel module: missing self-reference guard in map cleanup gives a use-after-freeCVE-2026-47597 · NVIDIA open GPU kernel module (Resource Server, map cleanup path)High
- NVIDIA open GPU kernel module: memory access permissions are lost during DMA mappingCVE-2026-47599 · NVIDIA open GPU kernel module for Linux (DMA mapping path)High
- NVIDIA GPU driver: error-handling path operates on an improperly initialized resourceCVE-2026-47600 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer, error handling)High
- NVIDIA open GPU kernel module: read-only DMA-BUF imported from another device becomes writableCVE-2026-47601 · NVIDIA open GPU kernel module (DMA-BUF import path)High
- Linux kernel amdgpu user-mode queues (doorbell submission path) (drm/amdgpu): A double free in the amdgpu user-modeCVE-2026-52987 · Linux kernel amdgpu user-mode queues (doorbell submission path) (drm/amdgpu)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.