GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA GPU driver: local user can make the kernel mode driver dereference an untrusted pointer

CVSS 7.1CVE-2026-47602NVIDIA / GPU stackcurated

Impact

An unprivileged local user can hand the kernel mode driver a pointer it trusts without validation, producing kernel memory disclosure or a driver crash. On a shared GPU node the disclosure path can leak kernel memory to a tenant process, and the crash path takes the GPU - and usually the node - out of service, which is expensive when jobs are long-running and the node cannot be drained cheaply. The affected product list includes the Virtual GPU Manager, so vGPU hosts are in scope as well as bare-metal nodes.

Who can reach it

Local user with low privileges and access to the GPU device nodes - any tenant with a GPU container qualifies. Authentication to the host is required, no privileged role is.

What to do

Update to the fixed driver and vGPU manager branches in NVIDIA bulletin 2026/5861. Drain the node and reboot to swap the kernel modules; on vGPU hosts the guests must be evacuated first.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.