GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA Windows GPU driver: unprivileged user causes an out-of-bounds write in the kernel mode layer

CVSS 7.8CVE-2026-47593NVIDIA / GPU stackcurated

Impact

An unprivileged local user can write past a kernel allocation in the Windows GPU driver. NVIDIA lists code execution, privilege escalation and denial of service for this one, without the information-disclosure outcome attached to most of the bulletin, which is consistent with a write-only primitive. For an operator running Windows GPU guests, this is a straightforward in-guest path to SYSTEM.

Who can reach it

Local, unprivileged. Any user process on an affected Windows host or guest, including the guest driver inside a vGPU VM.

What to do

Apply the Windows driver branch from NVIDIA bulletin 2026/5861; the record names no fixed version. Reboot each updated Windows GPU instance, which requires draining it first.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.