GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA GPU driver for Linux: read-only memory becomes writable because permissions are not preserved

CVSS 7.0CVE-2026-47596NVIDIA / GPU stackcurated

Impact

The kernel mode layer loses memory protection attributes, letting an unprivileged user write to memory that should be read-only, with code execution and privilege escalation as the stated outcomes. The scope is marked changed (S:C), so the damage reaches beyond the attacker's own boundary. The vector is AV:P - NVIDIA scored this as requiring physical access - which on a datacenter node means an operator or anyone with hands-on access in the cage rather than a remote tenant, so it ranks below the other 7.0 items for most fleets.

Who can reach it

Low-privileged local user, scored by NVIDIA as requiring physical access (AV:P) and high attack complexity.

What to do

Update the Linux GPU display driver and guest driver to the fixed branch in NVIDIA bulletin 2026/5861. Drain the node and reboot to reload the kernel modules. Given the physical-access vector, this can usually ride along with your next scheduled driver roll rather than an emergency window.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.