Description
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause an access of an uninitialized pointer. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Published: 2026-09-30
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Potential Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

NVIDIA GPU Display Driver for Windows and Linux contains a firmware flaw where an uninitialized pointer can be accessed by an attacker. This leads to possible code execution, denial of service, privilege escalation, information disclosure, and data tampering. The weakness is classified as CWE‑824, indicating that a program can access an object that has not been properly initialized.

Affected Systems

All NVIDIA GPU driver families—GeForce, RTX, Quadro, NVS, Tesla, and Virtual GPU Manager—are potentially affected, regardless of operating system. No specific affected firmware versions were supplied, implying the vulnerability may span multiple driver releases until patched.

Risk and Exploitability

The CVSS score of 7.8 signals high severity, but the EPSS score is not provided, making the probability of real-world exploitation unclear. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is local access to the GPU or privileged firmware execution. An attacker with sufficient access could exploit the uninitialized pointer to achieve arbitrary code execution or cause a denial of service on the host system.

Generated by OpenCVE AI on September 30, 2026 at 19:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the NVIDIA GPU driver firmware to the latest revision that addresses the uninitialized pointer issue.
  • Filter GPU access by using device isolation or virtualization controls to limit the exposure of drivers to untrusted code.
  • Monitor GPU driver logs for anomalous behavior and enforce strict access controls for privileged processes that interact with the GPU.

Generated by OpenCVE AI on September 30, 2026 at 19:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Title Firmware Vulnerability in NVIDIA GPU Drivers Allows Uninitialized Pointer Access

Wed, 30 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause an access of an uninitialized pointer. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Weaknesses CWE-824
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-09-30T17:59:52.331Z

Reserved: 2026-05-19T19:55:42.912Z

Link: CVE-2026-47528

cve-icon Vulnrichment

Updated: 2026-09-30T17:57:33.456Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T16:17:19.327

Modified: 2026-09-30T18:18:24.363

Link: CVE-2026-47528

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T19:15:07Z

Weaknesses
  • CWE-824

    Access of Uninitialized Pointer