Description
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user could cause a use-after-free. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
Published: 2026-09-30
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Local Privilege Escalation and potential code execution
Action: Immediate Patch
AI Analysis

Impact

An unprivileged user can trigger a use‑after‑free in the NVIDIA GPU Display Driver on Windows and Linux, a flaw identified as CWE‑416. The vulnerability can lead to arbitrary code execution at the kernel level, allowing the attacker to elevate privileges, tamper with data, crash the system or expose sensitive information. The impact is limited to the local machine, but once privilege escalation is achieved, full system compromise becomes possible.

Affected Systems

Affected NVIDIA products include GeForce, Guest driver, RTX, Quadro, NVS, and Tesla GPUs. No specific driver version numbers are listed in the advisory, so any installation of the NVIDIA GPU Display Driver prior to the published fix may be vulnerable.

Risk and Exploitability

The CVSS score of 7.8 classifies the vulnerability as High severity. EPSS data is unavailable, and the flaw is not yet cataloged in CISA KEV. The likely attack vector is local, requiring the attacker to have permissions to run code on the target machine, such as through a user‑level application that interacts with the GPU. Successful exploitation can grant kernel privileges, effectively compromising the entire host.

Generated by OpenCVE AI on September 30, 2026 at 20:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest NVIDIA GPU driver releases that contain the fix for CVE-2026-47516.
  • If an immediate driver update is not feasible, temporarily disable or restrict GPU acceleration for applications that do not require it, to reduce the attack surface.
  • Continuously monitor system logs for unexpected access‑sequence failures or crash reports that may indicate exploitation attempts.

Generated by OpenCVE AI on September 30, 2026 at 20:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia geforce
Nvidia guest Driver
Nvidia nvs
Nvidia quadro
Nvidia rtx
Nvidia tesla
Vendors & Products Nvidia
Nvidia geforce
Nvidia guest Driver
Nvidia nvs
Nvidia quadro
Nvidia rtx
Nvidia tesla

Wed, 30 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in NVIDIA GPU Display Driver Enables Local Privilege Escalation

Wed, 30 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user could cause a use-after-free. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-10-01T03:56:27.080Z

Reserved: 2026-05-19T19:55:42.108Z

Link: CVE-2026-47516

cve-icon Vulnrichment

Updated: 2026-09-30T17:57:36.756Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T16:17:17.410

Modified: 2026-10-01T04:18:10.840

Link: CVE-2026-47516

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T04:30:18Z

Weaknesses