Description
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an integer underflow. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Published: 2026-09-30
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation / Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The NVIDIA GPU Display Driver for Windows and Linux contains a kernel mode layer vulnerability where an attacker could cause an integer underflow. A successful exploit of this flaw could result in code execution, denial of service, escalation of privileges, information disclosure, and data tampering. The description indicates an integer underflow that may lead to arbitrary memory corruption within the driver’s kernel space.

Affected Systems

Affected systems include NVIDIA GeForce, RTX, Quadro, NVS, Tesla GPUs, and the NVIDIA Virtual GPU Manager, across both Windows and Linux operating systems. No specific driver versions are listed, so all current versions that include the kernel mode component are potentially vulnerable.

Risk and Exploitability

The CVSS score of 7.8 classifies this vulnerability as high severity, indicating significant risk to memory integrity and privilege boundaries. The EPSS score is not available, so the exact likelihood of exploitation remains unknown, and the vulnerability is not listed in the CISA KEV catalog. Based on the description of an integer underflow in a kernel‑mode driver, the most likely exploitation path involves triggering the driver’s kernel mode path with crafted data from software running on the same host. An attacker who can deliver malicious payloads to the GPU device could exploit the flaw to execute arbitrary code, crash the driver, or gain elevated privileges, as inferred from the potential impact statements provided. The attack vector is inferred to be local or privileged, as remote exploitation would require exposure of driver interfaces to external actors, which is not explicitly documented.

Generated by OpenCVE AI on September 30, 2026 at 19:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest NVIDIA GPU driver updates that contain the kernel‑mode patch as soon as they are released.
  • If a patch is not yet available, enforce strict access controls on GPU device files or APIs to limit untrusted processes from interacting with the driver, effectively isolating the vulnerable kernel component.
  • Keep up‑to‑date with NVIDIA security advisories and apply any interim workarounds or mitigations they publish, such as disabling specific driver features or falling back to a known safe driver version until the official fix is distributed.

Generated by OpenCVE AI on September 30, 2026 at 19:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Title Integer Underflow in NVIDIA GPU Display Driver Kernel Mode Leading to Privilege Escalation

Wed, 30 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an integer underflow. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Weaknesses CWE-191
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-09-30T17:59:52.068Z

Reserved: 2026-05-19T19:55:43.813Z

Link: CVE-2026-47540

cve-icon Vulnrichment

Updated: 2026-09-30T17:57:30.862Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T16:17:21.290

Modified: 2026-09-30T18:18:26.183

Link: CVE-2026-47540

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T19:15:07Z

Weaknesses
  • CWE-191

    Integer Underflow (Wrap or Wraparound)