GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA open GPU kernel module: memory access permissions are lost during DMA mapping

CVSS 7.8CVE-2026-47599NVIDIA / GPU stackcurated

Impact

When the open-source kernel module sets up a DMA mapping it does not carry the original access permissions through, so an unprivileged local user can end up with a device-visible mapping that is more permissive than the memory it points at. DMA mappings are reachable by the GPU itself, so the window is not limited to what the CPU side can do. Operators running the open kernel modules on datacenter boards are exposed; this is the module flavour NVIDIA now ships by default for Turing and later.

Who can reach it

Local, unprivileged. A tenant process or container with access to the NVIDIA device nodes can request the mapping; no elevated privilege and no authentication are needed.

What to do

Update to the driver branch NVIDIA lists in bulletin 2026/5861 (the record gives no fixed version). The open kernel modules have to be rebuilt or reinstalled and reloaded, so drain the node and reboot it; if you build the modules with DKMS, confirm the rebuild actually ran before putting the node back in service.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.