NVIDIA open GPU kernel module: memory access permissions are lost during DMA mapping
Impact
When the open-source kernel module sets up a DMA mapping it does not carry the original access permissions through, so an unprivileged local user can end up with a device-visible mapping that is more permissive than the memory it points at. DMA mappings are reachable by the GPU itself, so the window is not limited to what the CPU side can do. Operators running the open kernel modules on datacenter boards are exposed; this is the module flavour NVIDIA now ships by default for Turing and later.
Who can reach it
Local, unprivileged. A tenant process or container with access to the NVIDIA device nodes can request the mapping; no elevated privilege and no authentication are needed.
What to do
Update to the driver branch NVIDIA lists in bulletin 2026/5861 (the record gives no fixed version). The open kernel modules have to be rebuilt or reinstalled and reloaded, so drain the node and reboot it; if you build the modules with DKMS, confirm the rebuild actually ran before putting the node back in service.
References
Related entries
- NVIDIA GPU driver: error-handling path operates on an improperly initialized resourceCVE-2026-47600 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer, error handling)High
- NVIDIA open GPU kernel module: read-only DMA-BUF imported from another device becomes writableCVE-2026-47601 · NVIDIA open GPU kernel module (DMA-BUF import path)High
- Linux kernel amdgpu user-mode queues (doorbell submission path) (drm/amdgpu): A double free in the amdgpu user-modeCVE-2026-52987 · Linux kernel amdgpu user-mode queues (doorbell submission path) (drm/amdgpu)High
- Linux kernel amdgpu display core (DC/DM) (drm/amd/display): An out-of-bounds access in the amdgpu display core (DC/DM)CVE-2026-53136 · Linux kernel amdgpu display core (DC/DM) (drm/amd/display)High
- Linux kernel amdgpu display core (DC/DM) (drm/amd/display): An out-of-bounds access in the amdgpu display core (DC/DM)CVE-2026-53137 · Linux kernel amdgpu display core (DC/DM) (drm/amd/display)High
- Linux accel/ivpu: signed truncation of firmware data_size overflows a stack buffer on IPC receiveCVE-2026-53202 · Linux kernel accel/ivpu (Intel NPU driver, IPC receive path)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.