Description
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Published: 2026-09-30
Score: 6.7 Medium
EPSS: n/a
KEV: No
Impact: Code execution
Action: Immediate Patch
AI Analysis

Impact

NVIDIA GPU Display Driver for Linux contains a kernel mode vulnerability that allows an attacker to perform an out‑of‑bounds write in the driver’s memory. This flaw can lead to code execution, system denial of service, escalation of privileges, information disclosure, and data tampering. The CVE description only states that a successful exploit might enable these outcomes; it does not explicitly claim remote or local attack capability, so the impact is described in terms of potential exploitation of the vulnerable code.

Affected Systems

The vulnerability affects NVIDIA’s Linux GPU drivers, impacting all GeForce, RTX, Quadro, NVS, and Tesla product families. No specific driver revisions are listed, so all currently installed drivers that contain the vulnerable code are potentially affected.

Risk and Exploitability

The CVSS score of 6.7 indicates a medium severity vulnerability. EPSS data is not available and the issue is not listed in CISA’s KEV catalog, suggesting that exploitation is not yet widely observed. The likely attack surface is local or requires elevated privileges because the flawed code runs in kernel mode; however, the exact vector is not explicitly stated in the advisory, so the assessment is inferred from the nature of the vulnerability.

Generated by OpenCVE AI on September 30, 2026 at 19:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the NVIDIA GPU Display Driver on Linux to the latest version that contains a fix for the out‑of‑bounds write.
  • If no patch is immediately available, restrict driver usage by disabling GPU support on systems that do not require it or by moving the driver to a confined environment that limits kernel exposure.
  • Implement kernel hardening measures such as enabling SELinux or AppArmor policies that isolate the driver’s memory space, reducing the risk of arbitrary code execution.

Generated by OpenCVE AI on September 30, 2026 at 19:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia geforce
Nvidia nvs
Nvidia quadro
Nvidia rtx
Nvidia tesla
Vendors & Products Nvidia
Nvidia geforce
Nvidia nvs
Nvidia quadro
Nvidia rtx
Nvidia tesla

Thu, 01 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
Title NVIDIA Linux GPU Driver Kernel Out‑of‑Bounds Write Vulnerability nvidia-driver: xorg-x11-drv-nvidia: nvidia-driver: arbitrary code execution via out-of-bounds write in kernel mode layer
Metrics threat_severity

None

threat_severity

Moderate


Wed, 30 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Title NVIDIA Linux GPU Driver Kernel Out‑of‑Bounds Write Vulnerability

Wed, 30 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-09-30T17:59:47.124Z

Reserved: 2026-05-19T19:55:42.912Z

Link: CVE-2026-47529

cve-icon Vulnrichment

Updated: 2026-09-30T17:55:47.681Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T16:17:19.507

Modified: 2026-09-30T18:18:24.533

Link: CVE-2026-47529

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-30T15:52:43Z

Links: CVE-2026-47529 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T08:30:04Z

Weaknesses