Description
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an incorrect conversion between numeric types. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Published: 2026-09-30
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized code execution with escalation of privileges
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in NVIDIA’s GPU Display Driver for Windows and Linux, specifically within the kernel mode layer. A flawed numeric type conversion can be engineered by a malicious actor to execute arbitrary code, obtain elevated privileges, crash the system, exfiltrate data, or tamper with information. The exploit turns a simple type‑mismatch into a full privilege escalation and potential denial of service.

Affected Systems

Affected are all NVIDIA GPU products announced under the GeForce, RTX, Quadro, NVS, Tesla, and Virtual GPU Manager lines. The driver package applies to both Windows and Linux operating systems. Specific version details are not supplied by the CNA or advisory references, so any driver installation that predates the vendor’s latest security release is potentially vulnerable.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity attack path. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The kernel mode context suggests a local privilege escalation vector, likely requiring a user with local access to load the vulnerable driver. Because the description states a conversion error in kernel space, the attacker would need to execute the malformed input through driver interaction, which is inferred rather than explicitly documented. If successful, a local adversary could achieve full system compromise or cause the device to fail.

Generated by OpenCVE AI on September 30, 2026 at 20:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest NVIDIA GPU drivers that contain the fix for the kernel mode numeric type conversion issue.
  • If an immediate update is unavailable, enforce driver signing enforcement and restrict local administrative privileges to mitigate potential local exploitation.
  • Continuously monitor NVIDIA security advisories and apply subsequent patches as soon as they are released.

Generated by OpenCVE AI on September 30, 2026 at 20:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia geforce
Nvidia nvs
Nvidia quadro
Nvidia rtx
Nvidia tesla
Nvidia virtual Gpu Manager
Vendors & Products Nvidia
Nvidia geforce
Nvidia nvs
Nvidia quadro
Nvidia rtx
Nvidia tesla
Nvidia virtual Gpu Manager

Thu, 01 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
Title Kernel Mode Numeric Type Conversion Vulnerability Allows Arbitrary Code Execution and Privilege Escalation nvidia-driver: xorg-x11-drv-nvidia: nvidia-driver: Code execution via incorrect numeric type conversion
Metrics threat_severity

None

threat_severity

Important


Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title Kernel Mode Numeric Type Conversion Vulnerability Allows Arbitrary Code Execution and Privilege Escalation

Wed, 30 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an incorrect conversion between numeric types. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Weaknesses CWE-681
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-10-01T03:56:11.277Z

Reserved: 2026-05-19T19:55:41.287Z

Link: CVE-2026-47508

cve-icon Vulnrichment

Updated: 2026-09-30T17:57:46.303Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T16:17:16.110

Modified: 2026-10-01T04:18:09.500

Link: CVE-2026-47508

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-30T15:49:44Z

Links: CVE-2026-47508 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T11:45:07Z

Weaknesses
  • CWE-681

    Incorrect Conversion between Numeric Types