high · CVSS v3 7.8
CVE-2026-47500
NVIDIA GPU Display Driver contains a kernel‑mode use‑after‑free due to improper reference‑count cleanup. The flaw can allow local attackers
Overview
NVIDIA GPU Display Driver contains a kernel‑mode use‑after‑free due to improper reference‑count cleanup. The flaw can allow local attackers to execute code, crash the system, or gain elevated privileges. It affects both Windows and Linux drivers.
Description
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where improper cleanup of reference counts during error paths could lead to a use-after-free condition. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Impact
The vulnerability can compromise confidentiality, integrity, and availability of systems running NVIDIA GPU drivers. Local attackers could gain elevated privileges, execute arbitrary code, or cause a denial of service, potentially exposing sensitive data or disrupting operations.
Remediation
Apply the latest NVIDIA driver updates that fix the reference‑count cleanup bug. If immediate patching is not possible, restrict local user privileges, disable GPU acceleration for untrusted applications, and monitor for anomalous kernel activity.
Risk context
High severity (CVSS 7.8) indicates a serious flaw. Without a patch, attackers could exploit it to elevate privileges or crash systems, so timely remediation is recommended.
Affected products
- NVIDIA GPU Display Driver (Windows)
- NVIDIA GPU Display Driver (Linux)
Scores
- Severity
- high
- CVSS v2
- —
- CVSS v3
- 7.8
- CVSS v4
- —
- EPSS
- —