rootpwn

high · CVSS v3 7.8

CVE-2026-47500

NVIDIA GPU Display Driver contains a kernel‑mode use‑after‑free due to improper reference‑count cleanup. The flaw can allow local attackers

Overview

NVIDIA GPU Display Driver contains a kernel‑mode use‑after‑free due to improper reference‑count cleanup. The flaw can allow local attackers to execute code, crash the system, or gain elevated privileges. It affects both Windows and Linux drivers.

Description

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where improper cleanup of reference counts during error paths could lead to a use-after-free condition. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

Impact

The vulnerability can compromise confidentiality, integrity, and availability of systems running NVIDIA GPU drivers. Local attackers could gain elevated privileges, execute arbitrary code, or cause a denial of service, potentially exposing sensitive data or disrupting operations.

Remediation

Apply the latest NVIDIA driver updates that fix the reference‑count cleanup bug. If immediate patching is not possible, restrict local user privileges, disable GPU acceleration for untrusted applications, and monitor for anomalous kernel activity.

Risk context

High severity (CVSS 7.8) indicates a serious flaw. Without a patch, attackers could exploit it to elevate privileges or crash systems, so timely remediation is recommended.

Affected products

  • NVIDIA GPU Display Driver (Windows)
  • NVIDIA GPU Display Driver (Linux)

Scores

Severity
high
CVSS v2
—
CVSS v3
7.8
CVSS v4
—
EPSS
—

use-after-free kernel-mode privilege-escalation denial-of-service NVIDIA GPU driver Windows Linux

← All CVEs