Description
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause exposure of kernel stack contents including return addresses and pointers. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Published: 2026-09-30
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution and Privilege Escalation
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the kernel mode layer of NVIDIA GPU display drivers for Windows and Linux. A local user can trigger a fault that exposes kernel stack contents, including return addresses and pointers. This disclosure enables attackers to reverse engineer the execution path and potentially inject code, leading to arbitrary code execution, denial of service, privilege escalation, and information disclosure.

Affected Systems

All NVIDIA GPU drivers listed by the CNA, including GeForce, RTX, Quadro, NVS, Tesla, and the Guest driver for both Windows and Linux platforms. Versions are not specified in the advisory, so any installed driver at the time of the advisory could be affected.

Risk and Exploitability

The CVSS base score of 7.8 indicates a high severity for this flaw, while the EPSS score is unavailable and it is not yet cataloged in CISA's Known Exploited Vulnerabilities register, suggesting no widespread active exploitation yet. Without a published patch, the risk remains elevated for systems running NVIDIA drivers that have not yet been updated; a local attacker who can load malicious code into the driver could potentially elevate privileges or take control of the system. Therefore, timely mitigation is essential.

Generated by OpenCVE AI on September 30, 2026 at 19:04 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update NVIDIA GPU drivers to the latest version from the official NVIDIA website.
  • Verify that driver binaries are signed and exclude any debug or unsigned builds.
  • Restrict local user rights to limit privileges for loading kernel mode drivers and enforce least‑privilege policies.

Generated by OpenCVE AI on September 30, 2026 at 19:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Title Kernel Mode Driver Vulnerability Allowing Stack Disclosure and Remote Code Execution in NVIDIA GPU Drivers

Wed, 30 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause exposure of kernel stack contents including return addresses and pointers. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-09-30T17:59:52.725Z

Reserved: 2026-05-19T19:55:42.108Z

Link: CVE-2026-47514

cve-icon Vulnrichment

Updated: 2026-09-30T17:57:38.214Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T16:17:17.063

Modified: 2026-09-30T18:18:22.290

Link: CVE-2026-47514

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T19:15:07Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor