medium · CVSS v3 5.5
CVE-2026-47517
NVIDIA GPU Display Driver for Linux has a kernel mode driver flaw that can be triggered via a crafted ioctl, leading to a null pointer deref
Overview
NVIDIA GPU Display Driver for Linux has a kernel mode driver flaw that can be triggered via a crafted ioctl, leading to a null pointer dereference. This can cause a denial of service for the local user. The issue is limited to local privilege and does not allow code execution.
Description
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode driver where a local user may cause a null pointer dereference by submitting a crafted ioctl. A successful exploit of this vulnerability might lead to denial of service.
Impact
Denial of service affecting local user session; integrity and availability compromised; confidentiality not affected. Defenders should monitor for kernel panics and ensure driver updates.
Remediation
Apply the vendor patch that fixes the null pointer dereference in the kernel mode driver. Until patch, disable the driver or restrict ioctl access via SELinux/AppArmor. Monitor system logs for 'null pointer dereference' or 'kernel panic' events.
Risk context
Medium severity; no EPSS data available. Defenders should treat as moderate risk and apply patch promptly.
Affected products
- NVIDIA Linux GPU Driver
Scores
- Severity
- medium
- CVSS v2
- —
- CVSS v3
- 5.5
- CVSS v4
- —
- EPSS
- —