Description
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Published: 2026-09-30
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an out‑of‑bounds write in the kernel mode layer of NVIDIA’s GPU display driver for Windows and Linux. An attacker who can trigger the flaw may be able to execute arbitrary code, crash the system, or gain higher privileges. The impact potentially extends to code execution, denial of service, privilege escalation, information disclosure, and data tampering, which together could compromise confidentiality, integrity, and availability.

Affected Systems

Affected products include NVIDIA GeForce, RTX, Quadro, NVS, Tesla, and associated guest drivers on both Windows and Linux platforms. No specific version information is available from the CNA; the vulnerability is presumed to affect all current driver releases until patches are applied.

Risk and Exploitability

The CVSS score of 7.8 classifies the issue as high severity. EPSS data is not available, but the lack of a KEV listing does not negate the high risk posed. The attack likely requires the victim to be a local user or a program with GPU access, allowing a local privilege escalation path. Given the kernel‑mode nature of the flaw, exploitation would be feasible without needing network exposure if an attacker can supply malicious GPU commands or payloads.

Generated by OpenCVE AI on September 30, 2026 at 19:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update NVIDIA GPU drivers to a version that includes the fix for CVE-2026-47511
  • If an immediate patch is unavailable, consider disabling GPU acceleration or using a legacy driver version that is not affected by the bug in environments where security is paramount
  • Continuously monitor system logs for anomalous GPU activity and apply vendor security advisories when they become available

Generated by OpenCVE AI on September 30, 2026 at 19:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in NVIDIA GPU Display Driver Leading to Privilege Escalation

Wed, 30 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-09-30T17:59:53.122Z

Reserved: 2026-05-19T19:55:42.108Z

Link: CVE-2026-47511

cve-icon Vulnrichment

Updated: 2026-09-30T17:57:42.699Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T16:17:16.593

Modified: 2026-09-30T18:18:21.853

Link: CVE-2026-47511

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T19:15:07Z

Weaknesses