Description
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user can cause improper release of memory resources, leaving a mapping accessible after the underlying memory is reused. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Published: 2026-09-30
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Code Execution and Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The NVIDIA GPU Display Driver for Linux contains a flaw in the kernel mode layer where an unprivileged user can trigger improper release of memory resources. This mismanagement can leave a mapping accessible after the underlying memory is reused, potentially enabling arbitrary code execution, denial of service, privilege escalation, information disclosure, and data tampering, which compromise confidentiality, integrity, and availability.

Affected Systems

Affected systems include NVIDIA GPUs on Linux that use the GeForce, Guest Driver, RTX, Quadro, NVS, and Tesla product lines. The CNA data does not list specific driver versions, so administrators should verify the installed driver revision and apply updates accordingly.

Risk and Exploitability

The CVSS score of 7.8 conveys high severity. No EPSS score is available, so the current exploitation probability cannot be quantified, and the vulnerability is not referenced in the CISA KEV catalog. The likely attack scenario is that an unprivileged local user can exploit the kernel mode vulnerability to cause improper memory release, potentially executing code or escalating privileges on the host.

Generated by OpenCVE AI on September 30, 2026 at 19:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest NVIDIA GPU Display Driver for Linux that includes the patch for improper memory release.
  • Restrict kernel module loading so that only privileged users can load NVIDIA drivers and enforce unsigned module rejection.
  • Monitor the system for abnormal memory mapping or corruption events, audit driver permissions, and deprecate older driver versions before the patch is applied.

Generated by OpenCVE AI on September 30, 2026 at 19:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Title Improper Memory Release in NVIDIA Linux GPU Driver

Wed, 30 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user can cause improper release of memory resources, leaving a mapping accessible after the underlying memory is reused. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Weaknesses CWE-404
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-09-30T17:59:54.426Z

Reserved: 2026-05-19T19:55:40.488Z

Link: CVE-2026-47491

cve-icon Vulnrichment

Updated: 2026-09-30T17:57:58.032Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T16:17:13.433

Modified: 2026-09-30T18:18:19.087

Link: CVE-2026-47491

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T19:15:07Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release