CVE-2026-47558: Double Free
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause a double-free of imported memory state. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Affected Software
Event History
Frequently Asked Questions
Who is realistically exposed to exploitation?
Systems running the NVIDIA GPU Display Driver for Linux are affected. Exploitation requires a local unprivileged user, so remotely unauthenticated attackers are not the described threat model.
What level of access does an attacker need?
An attacker needs local access and low-level privileges sufficient to act as an unprivileged user. No user interaction is required according to the supplied vector.
What could a successful exploit allow?
Successful exploitation might enable code execution, denial of service, privilege escalation, information disclosure, and data tampering. The issue is a double-free involving imported memory state in the kernel-mode layer.