Description
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could cause an out-of-bounds write by supplying mismatched memory buffers during event buffer setup. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Published: 2026-09-30
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution and Privilege Escalation
Action: Assess Impact
AI Analysis

Impact

The vulnerability is a kernel‑mode out‑of‑bounds write caused by mismatched memory buffers during event buffer setup. Successful exploitation can lead to code execution, denial of service, privilege escalation, information disclosure, and data tampering. The weakness is classified as CWE‑787, an unbounded write flaw.

Affected Systems

Affected systems include NVIDIA GeForce, Quadro, NVS, RTX, and Tesla graphics drivers, as well as the Guest driver and Virtual GPU Manager for Linux. The vendor list enumerates these products, but specific version ranges are not disclosed, so any installation of these drivers on a Linux host could be susceptible until a patch is applied.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity attack. EPSS is not available, so the current exploitation probability cannot be quantified, and the vulnerability is not listed in CISA KEV. The flaw requires a local user to inject crafted buffers into the driver; therefore the attack vector is likely local with elevated privileges. Without mitigation, an attacker could execute arbitrary kernel code and fully compromise the host.

Generated by OpenCVE AI on September 30, 2026 at 19:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Download and install the latest NVIDIA driver package for Linux with the CVE‑2026‑47501 fix.
  • If no update is immediately available, restrict untrusted users from loading or accessing the NVIDIA GPU driver by using kernel lockdown or setting the driver to a non‑privileged module where possible.
  • Apply general kernel hardening by enabling SELinux or AppArmor profiles for GPU processes and using kernel hardening options such as CONFIG_KSTACK_ROOT or CONFIG_SECURITY_LOCKDOWN to reduce the impact of any remaining kernel memory vulnerabilities.

Generated by OpenCVE AI on September 30, 2026 at 19:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in NVIDIA Linux GPU Driver Allows Privilege Escalation

Wed, 30 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could cause an out-of-bounds write by supplying mismatched memory buffers during event buffer setup. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-09-30T17:59:54.036Z

Reserved: 2026-05-19T19:55:41.286Z

Link: CVE-2026-47501

cve-icon Vulnrichment

Updated: 2026-09-30T17:57:53.124Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T16:17:14.953

Modified: 2026-09-30T18:18:20.390

Link: CVE-2026-47501

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T19:15:07Z

Weaknesses