Description
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Published: 2026-09-30
Score: 6.7 Medium
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an out‑of‑bounds write in the Windows and Linux GPU display driver firmware. If an attacker can trigger the flaw, the firmware may accept data beyond allocated buffers, potentially allowing arbitrary memory corruption. This could result in code execution, privilege escalation, data tampering, or denial of service. The weakness is mapped to CWE-787.

Affected Systems

The flaw affects NVIDIA GPU products across several families, including GeForce, RTX, Quadro, NVS, and Tesla. All devices that use the affected GPU display driver on Windows or Linux are vulnerable, regardless of name or model. The description does not specify particular driver or firmware versions, so any installation of the current driver that contains the vulnerable code is at risk.

Risk and Exploitability

The CVSS score of 6.7 indicates moderate severity, while the EPSS score is not available and the vulnerability is not listed in the KEV catalog. Because the flaw occurs in firmware, a successful exploit would likely require the attacker to deliver a crafted payload via the driver’s interface or have local access to the device. The potential impact is significant, but exploitation is confined to systems with the vulnerable drivers. The risk is higher on machines that allow direct GPU interaction such as gaming or GPU‑accelerated workflows.

Generated by OpenCVE AI on September 30, 2026 at 17:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest NVIDIA GPU driver that includes the firmware patch.
  • If a newer driver cannot be installed, temporarily disable the GPU by uninstalling the driver or switching to a generic display driver.
  • Monitor system logs for unexpected memory write errors or driver crashes as potential exploitation indicators.

Generated by OpenCVE AI on September 30, 2026 at 17:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in NVIDIA GPU Firmware Enables Unauthorized Code Execution

Wed, 30 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the firmware where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-09-30T17:29:29.448Z

Reserved: 2026-05-19T19:55:43.812Z

Link: CVE-2026-47538

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T16:17:20.973

Modified: 2026-09-30T16:30:23.773

Link: CVE-2026-47538

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T17:30:19Z

Weaknesses