Description
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds read from kernel heap memory. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Published: 2026-09-30
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A kernel‑mode layer in the NVIDIA GPU Display Driver contains an out‑of‑bounds read flaw (CWE‑125) that can be triggered by a user. Exploitation could allow the attacker to read arbitrary kernel‑heap memory, potentially leading to code execution, denial of service, privilege escalation, information disclosure, or data tampering.

Affected Systems

NVIDIA GeForce, RTX, Quadro, NVS, and Tesla GPUs running the affected Windows or Linux display driver. No specific driver versions are listed, so any installation of these products during the period covered by the advisory may be impacted.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog. The description states that a successful exploitation may lead to code execution, denial of service, privilege escalation, information disclosure, or data tampering. The vulnerability is triggered by a user interacting with the driver, implying a local execution context. Remote exploitation is not documented in the CVE record and, if possible, would be an inferred scenario rather than a confirmed one. The lack of listed mitigations in the advisory means an exploit is plausible, especially on systems with unused or compromised GPU drivers.

Generated by OpenCVE AI on September 30, 2026 at 20:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Download and install the latest NVIDIA GPU Display Driver update that includes the kernel‑mode read fix.
  • If a driver update is unavailable, uninstall or disable the NVIDIA GPU display driver until a patch is released.
  • After installing the update or disabling the driver, reboot the system to ensure the new driver is active and the vulnerability is removed.

Generated by OpenCVE AI on September 30, 2026 at 20:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑bounds read in NVIDIA GPU Display Driver may lead to code execution nvidia-driver: nvidia-driver: arbitrary code execution via kernel heap out-of-bounds read
Metrics threat_severity

None

threat_severity

Important


Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑bounds read in NVIDIA GPU Display Driver may lead to code execution

Wed, 30 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an out-of-bounds read from kernel heap memory. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-10-01T03:56:14.157Z

Reserved: 2026-05-19T19:55:42.108Z

Link: CVE-2026-47513

cve-icon Vulnrichment

Updated: 2026-09-30T17:57:39.475Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T16:17:16.903

Modified: 2026-10-01T04:18:10.307

Link: CVE-2026-47513

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-30T15:49:49Z

Links: CVE-2026-47513 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T20:15:05Z

Weaknesses