rootpwn

high · CVSS v3 7.8

CVE-2026-47530

NVIDIA GPU Display Driver contains a kernel-mode out-of-bounds write that can lead to code execution. The flaw exists in both Windows and Li

Overview

NVIDIA GPU Display Driver contains a kernel-mode out-of-bounds write that can lead to code execution. The flaw exists in both Windows and Linux drivers. It is a high severity vulnerability that can be exploited by local or remote attackers.

Description

NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

Impact

Confidentiality: potential data leakage; Integrity: possible data tampering; Availability: denial of service. The vulnerability can be leveraged by attackers with local or remote access to gain elevated privileges or execute arbitrary code on affected systems.

Remediation

Apply the latest NVIDIA driver updates released after the CVE announcement. If updates are unavailable, disable GPU acceleration or block the driver from loading using group policy or device manager. Monitor for anomalous kernel activity and enforce least privilege for processes interacting with GPU drivers.

Risk context

High severity (CVSS 7.8) indicates significant risk; however, no EPSS data is available. Prompt patching is recommended to mitigate potential exploitation.

Affected products

  • NVIDIA GPU Display Driver for Windows
  • NVIDIA GPU Display Driver for Linux
  • NVIDIA GeForce drivers
  • NVIDIA Quadro drivers
  • NVIDIA Tesla drivers

Scores

Severity
high
CVSS v2
—
CVSS v3
7.8
CVSS v4
—
EPSS
—

nvidia gpu-driver kernel-mode out-of-bounds privilege-escalation code-execution denial-of-service

← All CVEs