Description
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds read leading to kernel information disclosure. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Published: 2026-09-30
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel information disclosure that can lead to code execution and privilege escalation
Action: Immediate Patch
AI Analysis

Impact

NVIDIA GPU Display Drivers for Windows and Linux contain an out‑of‑bounds read in the kernel‑mode component. A successful exploit can expose kernel memory contents, and the description states that such exposure might enable code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

Affected Systems

The flaw affects NVIDIA GPU Display Drivers on Windows and Linux for all NVIDIA GPU series, including GeForce, RTX, Quadro, NVS, and Tesla. No specific driver version information is provided, so any installation using the vulnerable driver should be considered at risk.

Risk and Exploitability

The CVSS score of 7.8 marks this vulnerability as high severity, and the EPSS score is not available. It is not listed in CISA KEV. The likely attack vector is inferred to require a local user with access to the GPU Driver, as the vulnerability resides in kernel mode. A local kernel read can provide the foundation for more severe attacks such as privilege escalation and code execution.

Generated by OpenCVE AI on September 30, 2026 at 20:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to the latest NVIDIA GPU Display Driver that resolves the kernel‑mode out‑of‑bounds read flaw.
  • If an update cannot be applied immediately, limit local user access to the GPU or segregate affected systems to reduce the potential exploitation surface.
  • Apply kernel integrity monitoring or audit logs to detect abnormal reads or privilege escalation attempts on the system.

Generated by OpenCVE AI on September 30, 2026 at 20:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia geforce
Nvidia nvs
Nvidia quadro
Nvidia rtx
Nvidia tesla
Vendors & Products Nvidia
Nvidia geforce
Nvidia nvs
Nvidia quadro
Nvidia rtx
Nvidia tesla

Thu, 01 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
Title NVIDIA GPU Driver Kernel‑Mode Out‑of‑Bounds Read Allowing Information Disclosure and Potential Privilege Escalation nvidia-driver: xorg-x11-drv-nvidia: nvidia-driver: privilege escalation via out-of-bounds read in kernel mode layer
Metrics threat_severity

None

threat_severity

Important


Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title NVIDIA GPU Driver Kernel‑Mode Out‑of‑Bounds Read Allowing Information Disclosure and Potential Privilege Escalation

Wed, 30 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds read leading to kernel information disclosure. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-10-01T03:56:13.455Z

Reserved: 2026-05-19T19:55:42.108Z

Link: CVE-2026-47512

cve-icon Vulnrichment

Updated: 2026-09-30T17:57:40.834Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T16:17:16.740

Modified: 2026-10-01T04:18:10.147

Link: CVE-2026-47512

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-30T15:49:47Z

Links: CVE-2026-47512 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T14:30:07Z

Weaknesses