NVIDIA GPU driver: error-handling path operates on an improperly initialized resource
Impact
When an operation fails, the cleanup path touches a resource that was never fully initialized, so the driver acts on uninitialized memory. Error paths are the easiest part of a driver for a local attacker to reach, because failure can be forced on demand with bad arguments or resource exhaustion. The outcome NVIDIA lists runs up to code execution in the privileged kernel module on the GPU node.
Who can reach it
Local, unprivileged. A tenant container or local user that can make a driver call fail; the NVIDIA device nodes are the only prerequisite.
What to do
Install the driver update named in NVIDIA bulletin 2026/5861; no fixed version is given in this record. Drain each GPU node and reboot so the fixed module loads; guest drivers in VMs need the same update.
References
Related entries
- NVIDIA open GPU kernel module: read-only DMA-BUF imported from another device becomes writableCVE-2026-47601 · NVIDIA open GPU kernel module (DMA-BUF import path)High
- Linux kernel amdgpu user-mode queues (doorbell submission path) (drm/amdgpu): A double free in the amdgpu user-modeCVE-2026-52987 · Linux kernel amdgpu user-mode queues (doorbell submission path) (drm/amdgpu)High
- Linux kernel amdgpu display core (DC/DM) (drm/amd/display): An out-of-bounds access in the amdgpu display core (DC/DM)CVE-2026-53136 · Linux kernel amdgpu display core (DC/DM) (drm/amd/display)High
- Linux kernel amdgpu display core (DC/DM) (drm/amd/display): An out-of-bounds access in the amdgpu display core (DC/DM)CVE-2026-53137 · Linux kernel amdgpu display core (DC/DM) (drm/amd/display)High
- Linux accel/ivpu: signed truncation of firmware data_size overflows a stack buffer on IPC receiveCVE-2026-53202 · Linux kernel accel/ivpu (Intel NPU driver, IPC receive path)High
- Linux kernel amdgpu kernel driver core (drm/amdgpu/jpeg): A correctness defect in the amdgpu kernel driver coreCVE-2026-63840 · Linux kernel amdgpu kernel driver core (drm/amdgpu/jpeg)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.