NVIDIA GPU driver: missing authorization lets a local user read another process's GPU channel state
Impact
The kernel mode driver fails to check authorization before exposing GPU channel state, so a local user can read the channel state belonging to another process. This is the cross-tenant case that matters most on a shared GPU: on a node where several pods or users share a device, one tenant can observe another tenant's GPU channel data, which can carry information about the work being run. NVIDIA scores it 5.5 with high confidentiality impact and no integrity or availability impact. NVIDIA split this same missing-authorization issue across two ids in bulletin 2026/5861 (CVE-2026-47603 and CVE-2026-47604) with identical descriptions, identical scores and one fix; they are covered here as one issue. Both Windows and Linux drivers are affected, including the Tesla datacenter branch, the vGPU guest driver and the Virtual GPU Manager.
Who can reach it
Local, authenticated: any user or tenant process that can open the NVIDIA kernel driver interfaces on a shared GPU node. No elevated privileges and no network access required.
What to do
Update the GPU driver to a version listed as fixed in NVIDIA security bulletin 2026/5861; the record does not name fixed versions. The update unloads the kernel modules, so drain and reboot each GPU node, and update the Virtual GPU Manager on vGPU hosts as well as the guest drivers. Where a reboot cannot be scheduled immediately, avoid co-scheduling untrusted tenants on the same physical GPU - MIG or whole-GPU-per-tenant placement reduces who shares a driver instance, but NVIDIA documents no mitigation that removes the flaw.
Also covers 1 CVE
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- NVIDIA Triton Inference Server: An absolute path traversal reachable from a local low-privileged account reaches codeCVE-2026-47630 · NVIDIA Triton Inference ServerMedium
- Linux kernel amdgpu display core (DC/DM) (drm/amd/display): A NULL pointer dereference in the amdgpu display coreCVE-2026-53135 · Linux kernel amdgpu display core (DC/DM) (drm/amd/display)Medium
- Linux kernel amdgpu display core (DC/DM) (drm/amd/display): Missing or insufficient validation of user-suppliedCVE-2026-53285 · Linux kernel amdgpu display core (DC/DM) (drm/amd/display)Medium
- Linux kernel amdgpu GEM/VM/command-submission ioctl surface (drm/amdgpu): A race condition or locking defectCVE-2026-53293 · Linux kernel amdgpu GEM/VM/command-submission ioctl surface (drm/amdgpu)Medium
- Linux kernel amdgpu display core (DC/DM) (drm/amd/display): A NULL pointer dereference in the amdgpu display coreCVE-2026-53313 · Linux kernel amdgpu display core (DC/DM) (drm/amd/display)Medium
- Linux kernel amdgpu RAS / GPU reset and recovery path (drm/amd/ras): A NULL pointer dereference in the amdgpu RAS / GPUCVE-2026-53315 · Linux kernel amdgpu RAS / GPU reset and recovery path (drm/amd/ras)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.