GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA open GPU kernel module: missing self-reference guard in map cleanup gives a use-after-free

CVSS 7.8CVE-2026-47597NVIDIA / GPU stackcurated

Impact

The Resource Server's map cleanup path does not guard against an object referencing itself, so cleanup frees memory that is still in use. An unprivileged local user can set up the self-referencing mapping deliberately, which makes this more deterministic than a timing-dependent race. This is in the open-source kernel module that NVIDIA now ships by default on recent datacenter boards, so most current fleets are running the affected code.

Who can reach it

Local, unprivileged. Any tenant with a GPU pod or a local user with the NVIDIA device nodes.

What to do

Update to the driver branch from NVIDIA bulletin 2026/5861; the record states no fixed version. Rebuild or reinstall the open kernel modules, then drain and reboot each GPU node; verify DKMS rebuilt the module before returning the node to the pool.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.