rootpwn

medium · CVSS v3 5.5

CVE-2026-47517

NVIDIA GPU Display Driver for Linux has a kernel mode driver flaw that can be triggered via a crafted ioctl, leading to a null pointer deref

Overview

NVIDIA GPU Display Driver for Linux has a kernel mode driver flaw that can be triggered via a crafted ioctl, leading to a null pointer dereference. This can cause a denial of service for the local user. The issue is limited to local privilege and does not allow code execution.

Description

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode driver where a local user may cause a null pointer dereference by submitting a crafted ioctl. A successful exploit of this vulnerability might lead to denial of service.

Impact

Denial of service affecting local user session; integrity and availability compromised; confidentiality not affected. Defenders should monitor for kernel panics and ensure driver updates.

Remediation

Apply the vendor patch that fixes the null pointer dereference in the kernel mode driver. Until patch, disable the driver or restrict ioctl access via SELinux/AppArmor. Monitor system logs for 'null pointer dereference' or 'kernel panic' events.

Risk context

Medium severity; no EPSS data available. Defenders should treat as moderate risk and apply patch promptly.

Affected products

  • NVIDIA Linux GPU Driver

Scores

Severity
medium
CVSS v2
—
CVSS v3
5.5
CVSS v4
—
EPSS
—

kernel driver null-pointer denial-of-service local NVIDIA Linux patch

← All CVEs