GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA open GPU kernel module: use-after-free in the event delivery path races file close

CVSS 7.0CVE-2026-47598NVIDIA / GPU stackcurated

Impact

An unprivileged local user can race asynchronous event delivery against closing the driver file descriptor and free memory that the driver still uses. NVIDIA lists code execution and privilege escalation among the outcomes, which on a GPU node means a tenant process escaping to host kernel context. This one is in the open-source kernel module, the variant most GPU clouds now run, and the affected list includes the guest driver and the Virtual GPU Manager. Races like this are also a reliable way to panic a node, which costs the running jobs.

Who can reach it

Local unprivileged user holding an open handle to the NVIDIA device nodes - any tenant with a GPU pod. High attack complexity because a race must be won.

What to do

Update the open GPU kernel module / driver to the fixed branch in NVIDIA bulletin 2026/5861. Module replacement requires the GPUs to be idle: drain the node and reboot.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.