Description
NVIDIA Linux GPU Display Driver contains a vulnerability in the NGX updater where an outdated embedded cryptographic library is susceptible to type confusion. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, or data tampering.
Published: 2026-09-30
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The NVIDIA Linux GPU Display Driver contains a type‑confusion vulnerability in the NGX updater caused by an outdated embedded cryptographic library. If successfully exploited, an attacker could achieve code execution, denial of service, information disclosure, or data tampering. This weakness can potentially allow privileged or local users to manipulate GPU driver behavior or compromise host processes.

Affected Systems

Affects NVIDIA Linux GPU drivers used in GeForce, RTX, Quadro, NVS, and Tesla product lines. Specific affected driver versions are not listed, so any release that includes the NGX updater is likely vulnerable until a fix is applied.

Risk and Exploitability

The CVSS v3 score of 7.8 indicates high severity, but no EPSS data is available, and the vulnerability is not listed in the CISA KEV. The attack vector is likely local, as the NGX updater runs within the driver context; remote exploitation would require additional steps such as a driver exploitation chain. Because the weakness is a type confusion in a cryptographic routine, exploitation would need precise conditions, so the risk is significant but exploitation is non‑trivial.

Generated by OpenCVE AI on September 30, 2026 at 19:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the NVIDIA Linux GPU driver to the latest official release that contains the NGX updater patch.
  • If a newer driver is unavailable, disable the NGX updater component or remove it from the installation to eliminate the vulnerable code path.
  • Restrict user privileges to prevent unauthorized driver updates and regularly audit the driver for anomalous behavior.

Generated by OpenCVE AI on September 30, 2026 at 19:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Title Type Confusion in NVIDIA Linux GPU NGX Updater

Wed, 30 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description NVIDIA Linux GPU Display Driver contains a vulnerability in the NGX updater where an outdated embedded cryptographic library is susceptible to type confusion. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, or data tampering.
Weaknesses CWE-843
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-09-30T17:59:53.779Z

Reserved: 2026-05-19T19:55:41.286Z

Link: CVE-2026-47504

cve-icon Vulnrichment

Updated: 2026-09-30T17:57:50.554Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T16:17:15.423

Modified: 2026-09-30T18:18:20.837

Link: CVE-2026-47504

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T19:15:07Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')