Description
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause improper input validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Published: 2026-09-30
Score: 6.7 Medium
EPSS: n/a
KEV: No
Impact: Kernel Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability lies in NVIDIA’s GPU Display Driver for Windows and Linux, specifically in the kernel‑mode layer where input validation is insufficient. This flaw permits an attacker to manipulate kernel memory, potentially enabling arbitrary code execution, denial of service, privilege escalation, information disclosure, and data tampering. The weakness is a classic input validation error, identified as CWE‑20.

Affected Systems

Angled systems include all NVIDIA graphics families—GeForce, RTX, Quadro, NVS, and Tesla—across both Windows and Linux platforms. The public advisory does not specify affected driver releases, so any current GPU display driver installation is considered vulnerable until a vendor‑issued patch is applied.

Risk and Exploitability

The CVSS rating of 6.7 indicates a moderate severity, yet the potential for kernel‑level code execution elevates the risk for local attackers. The EPSS score is not provided, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited known exploitation data as of now. Based on the description, it is inferred that an attacker would need to deliver crafted input to the kernel driver, likely via a privileged process or a compromised application with sufficient kernel access, to trigger the flaw.

Generated by OpenCVE AI on September 30, 2026 at 19:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest NVIDIA GPU Display Driver update available from NVIDIA’s official website.
  • Restart the system to load the updated driver and apply the fix.
  • Configure operating‑system access controls to restrict driver interaction to trusted processes only and to limit unprivileged user access to kernel‑mode components.
  • Monitor kernel logs and system behavior for anomalous activity that could indicate exploitation attempts.

Generated by OpenCVE AI on September 30, 2026 at 19:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia geforce
Nvidia nvs
Nvidia quadro
Nvidia rtx
Nvidia tesla
Vendors & Products Nvidia
Nvidia geforce
Nvidia nvs
Nvidia quadro
Nvidia rtx
Nvidia tesla

Wed, 30 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Title Kernel-Mode Input Validation Exploit in NVIDIA GPU Display Driver

Wed, 30 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause improper input validation. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-10-01T03:56:29.266Z

Reserved: 2026-05-19T19:55:42.911Z

Link: CVE-2026-47522

cve-icon Vulnrichment

Updated: 2026-09-30T17:55:53.062Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T16:17:18.320

Modified: 2026-10-01T04:18:11.720

Link: CVE-2026-47522

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T08:45:03Z

Weaknesses
  • CWE-20

    Improper Input Validation