Description
NVIDIA GPU Display Driver for Linux contains a vulnerability where a user might be able to cause a format string issue. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
Published: 2026-09-30
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Remote code execution
Action: Immediate Patch
AI Analysis

Impact

NVIDIA GPU Display Driver for Linux contains a format string flaw that an attacker could exploit to achieve code execution, privilege escalation, data tampering, denial of service, and information disclosure, as detailed in the vendor’s description.

Affected Systems

The issue affects NVIDIA GeForce, RTX, Quadro, NVS, and Tesla GPUs running their Linux display driver. The specific driver versions are not listed in the available information, so any Linux system using this driver family could be impacted.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity vulnerability, but the EPSS score is unavailable, and the vulnerability is not present in the CISA KEV catalog. Based on the description, the likely attack vector is local, requiring a user to invoke the vulnerable driver component. The vulnerability relies on an improper format string handler (CWE‑134), which can allow arbitrary code execution when an attacker supplies crafted input to the driver. The high severity and local nature suggest a considerable risk to affected systems if the driver is not updated promptly.

Generated by OpenCVE AI on September 30, 2026 at 19:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply NVIDIA’s latest GPU Display Driver for Linux that includes the fix for the format string vulnerability.
  • If an update cannot be applied immediately, uninstall or otherwise disable the vulnerable display driver modules to remove the attack surface.
  • Restrict local users from loading or executing kernel modules by ensuring only privileged accounts have the required permissions or by enforcing policy tools such as SELinux or AppArmor to block unauthorized module loading.

Generated by OpenCVE AI on September 30, 2026 at 19:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia geforce
Nvidia nvs
Nvidia quadro
Nvidia rtx
Nvidia tesla
Vendors & Products Nvidia
Nvidia geforce
Nvidia nvs
Nvidia quadro
Nvidia rtx
Nvidia tesla

Thu, 01 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
Title nvidia-driver: nvidia-driver: Arbitrary code execution via format string flaw
Metrics threat_severity

None

threat_severity

Important


Wed, 30 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description NVIDIA GPU Display Driver for Linux contains a vulnerability where a user might be able to cause a format string issue. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
Weaknesses CWE-134
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-10-01T03:56:00.875Z

Reserved: 2026-05-19T19:55:40.488Z

Link: CVE-2026-47494

cve-icon Vulnrichment

Updated: 2026-09-30T17:57:56.627Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T16:17:13.893

Modified: 2026-10-01T04:18:05.617

Link: CVE-2026-47494

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-30T15:49:26Z

Links: CVE-2026-47494 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T03:00:14Z

Weaknesses
  • CWE-134

    Use of Externally-Controlled Format String