high · CVSS v3 7.8
CVE-2026-47489
NVIDIA GPU Display Driver for Linux has a kernel-mode permission issue that can allow attackers to execute code or cause denial of service.
Overview
NVIDIA GPU Display Driver for Linux has a kernel-mode permission issue that can allow attackers to execute code or cause denial of service. The flaw affects systems running the driver on Linux platforms. It is a high severity vulnerability that can lead to privilege escalation and data tampering.
Description
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where permissions on read-only memory might not be preserved. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Impact
The vulnerability can compromise confidentiality, integrity, and availability of the affected system. Attackers may gain elevated privileges, execute arbitrary code, or disrupt normal operation. Defenders should consider the risk to all Linux hosts using NVIDIA graphics drivers.
Remediation
Apply the latest NVIDIA driver update that addresses the permission handling bug. If an update is not immediately available, restrict kernel module loading to trusted users and enforce strict SELinux/AppArmor policies. Monitor for anomalous kernel module activity.
Risk context
Severity is high with a CVSS v3 score of 7.8. No EPSS data is available, but the lack of a patch means the risk remains significant until mitigations are applied.
Affected products
- NVIDIA GPU Display Driver for Linux
Scores
- Severity
- high
- CVSS v2
- —
- CVSS v3
- 7.8
- CVSS v4
- —
- EPSS
- —