Description
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an integer overflow leading to an out-of-bounds write to GPU memory. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Published: 2026-09-30
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Potential Privilege Escalation and Code Execution
Action: Immediate Patch
AI Analysis

Impact

The NVIDIA GPU Display Driver for Windows and Linux contains an integer overflow vulnerability in its kernel mode layer that can lead to an out‑of‑bounds write into GPU memory. A successful exploit could allow an attacker to execute arbitrary code, cause a denial of service, elevate privileges, disclose information, or tamper with data. The weakness is categorized as CWE‑190, indicating an unsigned or signed integer overflow. The impact scope ranges from local escalation to full system compromise depending on the attacker’s initial access level.

Affected Systems

The vulnerability affects all NVIDIA GPU drivers for GeForce, Guest Driver, RTX, Quadro, NVS, and Tesla families on both Windows and Linux platforms. No specific version information is provided, so all current releases of these drivers are potentially impacted until a patch is applied.

Risk and Exploitability

The CVSS base score of 7.8 places this bug in the high‑severity range. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no confirmed widespread exploitation yet. The likely attack vector is inferred to be local via a user with GPU access or through remote code execution if the driver is exposed over network interfaces; however, the exact prerequisites for exploitation are not detailed in the description.

Generated by OpenCVE AI on September 30, 2026 at 19:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest NVIDIA GPU driver update that addresses the integer overflow in the kernel mode layer
  • Restrict privileged access to GPU driver components by ensuring only trusted administrators have installation rights
  • Monitor system logs and GPU memory usage for anomalous activity that may indicate an attempt to exploit the overflow

Generated by OpenCVE AI on September 30, 2026 at 19:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Title Integer Overflow in NVIDIA GPU Display Driver Kernel Mode Layer

Wed, 30 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an integer overflow leading to an out-of-bounds write to GPU memory. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Weaknesses CWE-190
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-09-30T17:59:53.248Z

Reserved: 2026-05-19T19:55:41.287Z

Link: CVE-2026-47510

cve-icon Vulnrichment

Updated: 2026-09-30T17:57:44.213Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T16:17:16.447

Modified: 2026-09-30T18:18:21.717

Link: CVE-2026-47510

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T19:15:07Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound