GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA GPU driver: error-handling path operates on an improperly initialized resource

CVSS 7.8CVE-2026-47600NVIDIA / GPU stackcurated

Impact

When an operation fails, the cleanup path touches a resource that was never fully initialized, so the driver acts on uninitialized memory. Error paths are the easiest part of a driver for a local attacker to reach, because failure can be forced on demand with bad arguments or resource exhaustion. The outcome NVIDIA lists runs up to code execution in the privileged kernel module on the GPU node.

Who can reach it

Local, unprivileged. A tenant container or local user that can make a driver call fail; the NVIDIA device nodes are the only prerequisite.

What to do

Install the driver update named in NVIDIA bulletin 2026/5861; no fixed version is given in this record. Drain each GPU node and reboot so the fixed module loads; guest drivers in VMs need the same update.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.