Description
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Published: 2026-09-30
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Update Driver
AI Analysis

Impact

The vulnerability resides in the kernel mode layer of NVIDIA's GPU Display Drivers for Windows and Linux, allowing an attacker to perform an out‑of‑bounds write. This defect can be exploited to execute arbitrary code, potentially leading to denial of service, privilege escalation, information disclosure, and data tampering. flaw is associated with CWE‑787, which represents data or control flow conditions enabling out‑of‑bounds writes.

Affected Systems

Affected products include NVIDIA GeForce, RTX, Quadro, NVS, and Tesla GPUs. No specific version details were supplied by the CNA, so any build running the vulnerable driver could be susceptible.

Risk and Exploitability

The CVSS score of 7.8 indicates a medium to high severity, and the vulnerability is not listed in CISA's KEV catalog. Since EPSS data is not available, the likelihood of exploitation in the wild remains uncertain. The attack likely requires local system presence to interact with the vulnerable driver, making it more relevant to privileged or local attackers. If exploited, it would compromise confidentiality, integrity, and availability of the affected system.

Generated by OpenCVE AI on September 30, 2026 at 19:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest NVIDIA GPU driver update that addresses the out-of-bounds write vulnerability.
  • If a newer driver cannot be applied, disable or remove the NVIDIA driver modules on Linux or the driver service on Windows until a patch is released.
  • Enable and configure endpoint detection and response to alert on abnormal GPU driver crashes or privilege escalation attempts, ensuring that security tools are updated.

Generated by OpenCVE AI on September 30, 2026 at 19:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia geforce
Nvidia nvs
Nvidia quadro
Nvidia rtx
Nvidia tesla
Vendors & Products Nvidia
Nvidia geforce
Nvidia nvs
Nvidia quadro
Nvidia rtx
Nvidia tesla

Thu, 01 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
Title nvidia-driver: nvidia-driver: Privilege escalation via out-of-bounds write in kernel mode layer
Metrics threat_severity

None

threat_severity

Important


Wed, 30 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-10-01T03:56:32.980Z

Reserved: 2026-05-19T19:55:42.912Z

Link: CVE-2026-47530

cve-icon Vulnrichment

Updated: 2026-09-30T17:57:32.230Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T16:17:19.667

Modified: 2026-10-01T04:18:12.260

Link: CVE-2026-47530

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-30T15:50:04Z

Links: CVE-2026-47530 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T21:30:12Z

Weaknesses