high · CVSS v3 7.8
CVE-2026-47510
NVIDIA GPU Display Driver for Windows and Linux contains a kernel-mode integer overflow that can cause an out-of-bounds write to GPU memory.
Overview
NVIDIA GPU Display Driver for Windows and Linux contains a kernel-mode integer overflow that can cause an out-of-bounds write to GPU memory. An attacker could exploit this to gain code execution or elevate privileges. The vulnerability affects all systems using NVIDIA GPU drivers on both operating systems.
Description
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause an integer overflow leading to an out-of-bounds write to GPU memory. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Impact
The flaw compromises confidentiality, integrity, and availability of systems that rely on NVIDIA GPU drivers. Attackers could execute arbitrary code, tamper with data, or crash the GPU subsystem, potentially disrupting critical workloads. Defenders should consider the risk when evaluating GPU usage in sensitive environments.
Remediation
Apply the latest NVIDIA driver updates that address CVE-2026-47510. If immediate patching is not possible, disable GPU acceleration for untrusted applications or isolate GPU workloads in virtual machines with restricted privileges. Monitor driver logs for anomalous memory access patterns and enforce least privilege for processes interacting with GPU drivers.
Risk context
Severity is high with a CVSS v3 score of 7.8. No EPSS data available, but the lack of a patch means the risk remains significant until updates are deployed. Defenders should treat this as a medium‑to‑high priority vulnerability.
Affected products
- NVIDIA GPU Display Driver for Windows
- NVIDIA GPU Display Driver for Linux
Scores
- Severity
- high
- CVSS v2
- —
- CVSS v3
- 7.8
- CVSS v4
- —
- EPSS
- —