GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA GPU driver: missing authorization lets a local user read another process's GPU channel state

CVSS 5.5CVE-2026-47603NVIDIA / GPU stack+1 more CVEscurated

Impact

The kernel mode driver fails to check authorization before exposing GPU channel state, so a local user can read the channel state belonging to another process. This is the cross-tenant case that matters most on a shared GPU: on a node where several pods or users share a device, one tenant can observe another tenant's GPU channel data, which can carry information about the work being run. NVIDIA scores it 5.5 with high confidentiality impact and no integrity or availability impact. NVIDIA split this same missing-authorization issue across two ids in bulletin 2026/5861 (CVE-2026-47603 and CVE-2026-47604) with identical descriptions, identical scores and one fix; they are covered here as one issue. Both Windows and Linux drivers are affected, including the Tesla datacenter branch, the vGPU guest driver and the Virtual GPU Manager.

Who can reach it

Local, authenticated: any user or tenant process that can open the NVIDIA kernel driver interfaces on a shared GPU node. No elevated privileges and no network access required.

What to do

Update the GPU driver to a version listed as fixed in NVIDIA security bulletin 2026/5861; the record does not name fixed versions. The update unloads the kernel modules, so drain and reboot each GPU node, and update the Virtual GPU Manager on vGPU hosts as well as the guest drivers. Where a reboot cannot be scheduled immediately, avoid co-scheduling untrusted tenants on the same physical GPU - MIG or whole-GPU-per-tenant placement reduces who shares a driver instance, but NVIDIA documents no mitigation that removes the flaw.

Also covers 1 CVE

The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.

CVE-2026-47604

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.