Description
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds array access. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Published: 2026-09-30
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Code execution
Action: Immediate Patch
AI Analysis

Impact

NVIDIA GPU Display Driver for Windows and Linux contains an out‑of‑bounds array access in its kernel‑mode layer. Based on the description, a user who can load the driver can trigger the flaw, potentially enabling arbitrary code execution at kernel privilege level, privilege escalation, denial of service, information disclosure, or tampering with data. The impact is local but can lead to full system compromise if exploited successfully.

Affected Systems

All NVIDIA GPU Display Drivers that support GeForce, RTX, Quadro, NVS, Tesla and Virtual GPU Manager product lines are affected. The precise version details are not published, but the issue resides in the kernel‑mode component common to all drivers on both Windows and Linux platforms.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity level. No EPSS probability score is available and the vulnerability is not yet catalogued in the CISA KEV list, suggesting limited or unconfirmed exploitation activity. Based on the description, the likely attack vector is local, requiring the ability to run code with the driver’s privileges. If exploited, the impact ranges from crashing the system to executing arbitrary code with kernel privileges, making vigilance and timely mitigation essential.

Generated by OpenCVE AI on October 1, 2026 at 02:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest NVIDIA GPU Display Driver that includes the kernel‑mode patch.
  • If an immediate update is unavailable, restrict or remove the vulnerable driver from systems that are not required to run it, or block the affected product from loading.
  • Apply the principle of least privilege to user accounts that may use GPU resources, limiting their ability to load or manipulate kernel drivers.

Generated by OpenCVE AI on October 1, 2026 at 02:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia geforce
Nvidia nvs
Nvidia quadro
Nvidia rtx
Nvidia tesla
Nvidia virtual Gpu Manager
Vendors & Products Nvidia
Nvidia geforce
Nvidia nvs
Nvidia quadro
Nvidia rtx
Nvidia tesla
Nvidia virtual Gpu Manager

Thu, 01 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
Title Kernel‑mode out‑of‑bounds array access vulnerability in NVIDIA GPU Display Drivers nvidia-driver: nvidia-driver: Privilege escalation via out-of-bounds array access in the kernel mode layer
Weaknesses CWE-787
Metrics threat_severity

None

threat_severity

Important


Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title Kernel‑mode out‑of‑bounds array access vulnerability in NVIDIA GPU Display Drivers

Wed, 30 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds array access. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Weaknesses CWE-129
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-10-01T03:56:10.516Z

Reserved: 2026-05-19T19:55:41.287Z

Link: CVE-2026-47507

cve-icon Vulnrichment

Updated: 2026-09-30T17:57:47.618Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T16:17:15.907

Modified: 2026-10-01T04:18:09.330

Link: CVE-2026-47507

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-30T15:49:43Z

Links: CVE-2026-47507 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T03:00:15Z

Weaknesses
  • CWE-129

    Improper Validation of Array Index

  • CWE-787

    Out-of-bounds Write