GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA open GPU kernel module: read-only DMA-BUF imported from another device becomes writable

CVSS 7.8CVE-2026-47601NVIDIA / GPU stackcurated

Impact

Importing a DMA-BUF exported by another device drops the read-only attribute, so the GPU side gains write access to a buffer the exporter intended to be read-only. This matters on nodes that share buffers between accelerators, NICs and the GPU, which is exactly the GPUDirect and RDMA style plumbing a training fleet runs. An unprivileged local user who can arrange such an import can corrupt memory owned by another subsystem.

Who can reach it

Local, unprivileged. Any process that can open the NVIDIA device nodes and a DMA-BUF exporter, which includes a tenant container given GPU and RDMA devices.

What to do

Apply the driver update referenced in NVIDIA bulletin 2026/5861; no fixed version is stated in this record. Replacing the kernel module requires stopping all GPU work on the node, so drain and reboot each affected host.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.