Description
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Published: 2026-09-30
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Potential remote code execution via kernel‑mode out‑of‑bounds write leading to privilege escalation, denial of service, information disclosure, and data tampering
Action: Immediate patch
AI Analysis

Impact

NVIDIA GPU Display Driver for Windows and Linux contains a kernel mode out‑of‑bounds write vulnerability that can be exploited to gain elevated privileges, execute arbitrary code, crash the system, and compromise confidentiality and integrity of data. The flaw allows a malicious actor to overwrite memory outside the bounds of a buffer, potentially enabling full control over the affected system.

Affected Systems

The vulnerability affects NVIDIA GPU Display Driver products including GeForce, RTX, Quadro, NVS, Tesla and Virtual GPU Manager on Windows and Linux platforms. No specific version numbers are supplied, so all currently installed drivers from these families should be treated as potential risk until a patch is released.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity. EPSS is not available and the vulnerability is not listed in CISA's KEV catalog, suggesting no mass exploitation has been observed yet. The attack vector is not explicitly defined; it is likely a local or privileged‑user exploit, though remote execution cannot be ruled out without further details.

Generated by OpenCVE AI on September 30, 2026 at 19:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update NVIDIA GPU Display Driver to the latest version when a patch is made available
  • Apply the vendor‑issued driver update as soon as it is released to address the kernel‑mode out‑of‑bounds write
  • Configure the system to run GPU drivers with the minimal required permissions and audit driver activity for anomalous behavior

Generated by OpenCVE AI on September 30, 2026 at 19:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Title Kernel Mode Out‑of‑Bounds Write in NVIDIA GPU Display Driver

Wed, 30 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-09-30T17:59:52.463Z

Reserved: 2026-05-19T19:55:42.911Z

Link: CVE-2026-47523

cve-icon Vulnrichment

Updated: 2026-09-30T17:57:34.983Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T16:17:18.493

Modified: 2026-09-30T18:18:23.590

Link: CVE-2026-47523

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T19:15:07Z

Weaknesses