Description
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an improper validation of an array index. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Published: 2026-09-30
Score: 6.7 Medium
EPSS: n/a
KEV: No
Impact: privilege escalation
Action: monitor
AI Analysis

Impact

The vulnerability arises from improper validation of an array index within NVIDIA’s GPU Display Driver kernel mode layer. This weakness, classified as CWE-129 and CWE-1285, can be abused by an attacker to achieve code execution, denial of service, and privilege escalation, potentially leading to information disclosure and data tampering. The risk extends beyond a single user as it affects the kernel driver that governs GPU operations.

Affected Systems

The issue impacts NVIDIA GPU Display Driver releases for Windows and Linux affecting product families such as GeForce, RTX, Quadro, NVS, and Tesla. No specific version information is currently provided, so all affected driver builds should be considered at risk until a vendor‑issued fix is applied.

Risk and Exploitability

With a CVSS score of 6.7 the vulnerability is of moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog, suggesting no known widespread exploitation yet. The likely attack vector is user‑level interaction with the driver, which could allow a malicious application or local attacker to trigger the unvalidated array access. Given the kernel‑mode nature of the flaw, successful exploitation could lead to full process compromise or system instability.

Generated by OpenCVE AI on October 1, 2026 at 02:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest NVIDIA GPU Display Driver update that implements strict array bounds checking to mitigate the CWE-129 and CWE-1285 weaknesses.
  • If a patch is not yet available, restrict GPU driver usage by disabling the driver or limiting application access to prevent kernel‑mode code execution.
  • Consider temporarily disabling non‑essential GPU features for critical systems until vendor remediation is released.

Generated by OpenCVE AI on October 1, 2026 at 02:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia geforce
Nvidia nvs
Nvidia quadro
Nvidia rtx
Nvidia rtx, Quadro, Nvs
Nvidia tesla
Vendors & Products Nvidia
Nvidia geforce
Nvidia nvs
Nvidia quadro
Nvidia rtx
Nvidia rtx, Quadro, Nvs
Nvidia tesla

Thu, 01 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
Title GPU Driver Kernel Mode Array Index Validation Failure nvidia-driver: nvidia-driver: Arbitrary code execution via improper array index validation
Weaknesses CWE-1285
Metrics threat_severity

None

threat_severity

Moderate


Wed, 30 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Title GPU Driver Kernel Mode Array Index Validation Failure

Wed, 30 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an improper validation of an array index. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Weaknesses CWE-129
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-09-30T17:59:47.383Z

Reserved: 2026-05-19T19:55:42.911Z

Link: CVE-2026-47525

cve-icon Vulnrichment

Updated: 2026-09-30T17:55:50.364Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T16:17:18.833

Modified: 2026-09-30T18:18:23.900

Link: CVE-2026-47525

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-30T15:52:41Z

Links: CVE-2026-47525 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T08:45:03Z

Weaknesses
  • CWE-1285

    Improper Validation of Specified Index, Position, or Offset in Input

  • CWE-129

    Improper Validation of Array Index