CVE-2026-47561: High severity Nvidia GPU Display Driver for Linux vulnerability
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where the size of an ioctl input buffer is not validated, allowing an unprivileged caller to trigger an out-of-bounds write in kernel memory. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Systems running the NVIDIA GPU Display Driver for Linux are affected by the vulnerable kernel-mode layer. Exploitation requires local access and low privileges; no user interaction is required.
What level of access does an attacker need to exploit it?
An attacker must already be able to run code locally as an unprivileged user and invoke the affected ioctl interface. The provided data does not indicate that remote exploitation is possible.
What could successful exploitation allow?
Successful exploitation might permit kernel-memory out-of-bounds writes, potentially resulting in code execution, denial of service, privilege escalation, information disclosure, or data tampering.