Bug#1149643: nvidia-open-gpu-kernel-modules: CVE-2026-47489 CVE-2026-47491 CVE-2026-47492 CVE-2026-47494 CVE-2026-47496 CVE-2026-47500 CVE-2026-47501 CVE-2026-47503 CVE-2026-47504 CVE-2026-47506 CVE-2026-47507 CVE-2026-47508 CVE-2026-47509 CVE-2026-47510 CVE-2026-47511 CVE-2026-47512 CVE-2026-47513 CVE-2026-47514 CVE-2026-47515 CVE-2026-47516 CVE-2026-47517 CVE-2026-47518 CVE-2026-47522 CVE-2026-47523 CVE-2026-47524 CVE-2026-47525 CVE-2026-47526 CVE-2026-47527 CVE-2026-47528 CVE-2026-47529 CVE-2026-47530 CVE-2026-47531 CVE-2026-47532 CVE-2026-47533 CVE-2026-47534 CVE-2026-47537 CVE-2026-47538 CVE-2026-47540 CVE-2026-47542 CVE-2026-47543 CVE-2026-47545 CVE-2026-47546 CVE-2026-47547 CVE-2026-47548 CVE-2026-47549 CVE-2026-47551 CVE-2026-47552 CVE-2026-47553 CVE-2026-47554 CVE-2026-47555 CVE-2026-47556 CVE-2026-47557 CVE-2026-47558 CVE-2026-47559 CVE-2026-47560 CVE-2026-47561 CVE-2026-47562 CVE-2026-47563 CVE-2026-47565 CVE-2026-47566 CVE-2026-47567 CVE-2026-47568 CVE-2026-47569 CVE-2026-47586 CVE-2026-47587 CVE-2026-47588 CVE-2026-47589 CVE-2026-47590 CVE-2026-47591 CVE-2026-47592 CVE-2026-47594 CVE-2026-47595 CVE-2026-47596 CVE-2026-47597 CVE-2026-47598 CVE-2026-47599 CVE-2026-47600 CVE-2026-47601 CVE-2026-47602 CVE-2026-47603 CVE-2026-47604
Moritz Mühlenhoff
jmm at inutil.org
Thu Oct 1 21:47:59 BST 2026
Source: nvidia-open-gpu-kernel-modules
X-Debbugs-CC: team at security.debian.org
Severity: grave
Tags: security
Hi,
The following vulnerabilities were published for nvidia-open-gpu-kernel-modules.
https://nvidia.custhelp.com/app/answers/detail/a_id/5747
CVE-2026-47489[0]:
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the
| kernel mode layer where permissions on read-only memory might not be
| preserved. A successful exploit of this vulnerability might lead to
| code execution, denial of service, escalation of privileges,
| information disclosure, and data tampering.
CVE-2026-47491[1]:
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the
| kernel mode layer where an unprivileged user can cause improper
| release of memory resources, leaving a mapping accessible after the
| underlying memory is reused. A successful exploit of this
| vulnerability might lead to code execution, denial of service,
| escalation of privileges, information disclosure, and data
| tampering.
CVE-2026-47492[2]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode layer, where an attacker can cause
| improper access control. A successful exploit of this vulnerability
| might lead to denial of service.
CVE-2026-47494[3]:
| NVIDIA GPU Display Driver for Linux contains a vulnerability where a
| user might be able to cause a format string issue. A successful
| exploit of this vulnerability might lead to code execution,
| escalation of privileges, data tampering, denial of service, and
| information disclosure.
CVE-2026-47496[4]:
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the
| Virtual GPU Manager (vGPU plugin) where a guest VM user may cause an
| out-of-bounds write by sending a specially crafted RPC call to the
| host. A successful exploit of this vulnerability might lead to
| escalation of privileges, data tampering, and denial of service.
CVE-2026-47500[5]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode layer where improper cleanup of
| reference counts during error paths could lead to a use-after-free
| condition. A successful exploit of this vulnerability might lead to
| code execution, denial of service, escalation of privileges,
| information disclosure, and data tampering.
CVE-2026-47501[6]:
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the
| kernel mode layer where a user could cause an out-of-bounds write by
| supplying mismatched memory buffers during event buffer setup. A
| successful exploit of this vulnerability might lead to code
| execution, denial of service, escalation of privileges, information
| disclosure, and data tampering.
CVE-2026-47503[7]:
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the
| Virtual GPU Manager (vGPU plugin), where a guest VM user may cause
| an out-of-bounds write by sending a crafted RPC message with invalid
| performance state list size parameters. A successful exploit of this
| vulnerability might lead to code execution, escalation of
| privileges, data tampering, denial of service, and information
| disclosure.
CVE-2026-47504[8]:
| NVIDIA Linux GPU Display Driver contains a vulnerability in the NGX
| updater where an outdated embedded cryptographic library is
| susceptible to type confusion. A successful exploit of this
| vulnerability might lead to code execution, denial of service,
| information disclosure, or data tampering.
CVE-2026-47506[9]:
| NVIDIA GPU Display Driver for Windows contains a vulnerability in
| the kernel-mode color transform path where excessive kernel stack
| use occurs when evaluating YCbCr420 display emulation. A successful
| exploit of this vulnerability might lead to denial of service.
CVE-2026-47507[10]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode layer, where a user could cause an
| out-of-bounds array access. A successful exploit of this
| vulnerability might lead to code execution, denial of service,
| escalation of privileges, information disclosure, and data
| tampering.
CVE-2026-47508[11]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode layer, where a user could cause an
| incorrect conversion between numeric types. A successful exploit of
| this vulnerability might lead to code execution, denial of service,
| escalation of privileges, information disclosure, and data
| tampering.
CVE-2026-47509[12]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode layer, where a user could cause an
| out-of-bounds write. A successful exploit of this vulnerability
| might lead to code execution, denial of service, escalation of
| privileges, information disclosure, and data tampering.
CVE-2026-47510[13]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode layer, where a user could cause an
| integer overflow leading to an out-of-bounds write to GPU memory. A
| successful exploit of this vulnerability might lead to code
| execution, denial of service, escalation of privileges, information
| disclosure, and data tampering.
CVE-2026-47511[14]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode layer, where a user could cause an
| out-of-bounds write. A successful exploit of this vulnerability
| might lead to code execution, denial of service, escalation of
| privileges, information disclosure, and data tampering.
CVE-2026-47512[15]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode layer, where a user could cause an
| out-of-bounds read leading to kernel information disclosure. A
| successful exploit of this vulnerability might lead to code
| execution, denial of service, escalation of privileges, information
| disclosure, and data tampering.
CVE-2026-47513[16]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode layer, where a user could cause an
| out-of-bounds read from kernel heap memory. A successful exploit of
| this vulnerability might lead to code execution, denial of service,
| escalation of privileges, information disclosure, and data
| tampering.
CVE-2026-47514[17]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode layer, where a user could cause
| exposure of kernel stack contents including return addresses and
| pointers. A successful exploit of this vulnerability might lead to
| code execution, denial of service, escalation of privileges,
| information disclosure, and data tampering.
CVE-2026-47515[18]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode layer, where a user could cause an
| out-of-bounds read via an unbounded string operation. A successful
| exploit of this vulnerability might lead to code execution, denial
| of service, escalation of privileges, information disclosure, and
| data tampering.
CVE-2026-47516[19]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability where an unprivileged user could cause a use-after-
| free. A successful exploit of this vulnerability might lead to code
| execution, escalation of privileges, data tampering, denial of
| service, and information disclosure.
CVE-2026-47517[20]:
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the
| kernel mode driver where a local user may cause a null pointer
| dereference by submitting a crafted ioctl. A successful exploit of
| this vulnerability might lead to denial of service.
CVE-2026-47518[21]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in a secure microcontroller component, where incorrect
| permission assignment for a critical resource allows an attacker
| with privileged local access to modify protected memory that should
| be restricted. A successful exploit of this vulnerability might lead
| to code execution and escalation of privileges.
CVE-2026-47522[22]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode layer where an attacker could cause
| improper input validation. A successful exploit of this
| vulnerability might lead to code execution, denial of service,
| escalation of privileges, information disclosure, and data
| tampering.
CVE-2026-47523[23]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode layer where an attacker could cause
| an out-of-bounds write. A successful exploit of this vulnerability
| might lead to code execution, denial of service, escalation of
| privileges, information disclosure, and data tampering.
CVE-2026-47524[24]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode layer where an attacker could cause
| an out-of-bounds read. A successful exploit of this vulnerability
| might lead to code execution, denial of service, escalation of
| privileges, information disclosure, and data tampering.
CVE-2026-47525[25]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode layer where an attacker could cause
| an improper validation of an array index. A successful exploit of
| this vulnerability might lead to code execution, denial of service,
| escalation of privileges, information disclosure, and data
| tampering.
CVE-2026-47526[26]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the firmware where an attacker could cause a null
| pointer dereference. A successful exploit of this vulnerability
| might lead to denial of service.
CVE-2026-47527[27]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the firmware where an attacker could cause an out-
| of-bounds read. A successful exploit of this vulnerability might
| lead to code execution, denial of service, escalation of privileges,
| information disclosure, and data tampering.
CVE-2026-47528[28]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the firmware where an attacker could cause an
| access of an uninitialized pointer. A successful exploit of this
| vulnerability might lead to code execution, denial of service,
| escalation of privileges, information disclosure, and data
| tampering.
CVE-2026-47529[29]:
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the
| kernel mode layer where an attacker could cause an out-of-bounds
| write. A successful exploit of this vulnerability might lead to code
| execution, denial of service, escalation of privileges, information
| disclosure, and data tampering.
CVE-2026-47530[30]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode layer where an attacker could cause
| an out-of-bounds write. A successful exploit of this vulnerability
| might lead to code execution, denial of service, escalation of
| privileges, information disclosure, and data tampering.
CVE-2026-47531[31]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode layer where an attacker could cause
| a null pointer dereference. A successful exploit of this
| vulnerability might lead to denial of service.
CVE-2026-47532[32]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode layer where an attacker could cause
| an out-of-bounds write. A successful exploit of this vulnerability
| might lead to code execution, denial of service, escalation of
| privileges, information disclosure, and data tampering.
CVE-2026-47533[33]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode layer where an attacker could cause
| an improper validation of an array index. A successful exploit of
| this vulnerability might lead to code execution, denial of service,
| escalation of privileges, information disclosure, and data
| tampering.
CVE-2026-47534[34]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode layer where an attacker could cause
| a divide by zero. A successful exploit of this vulnerability might
| lead to denial of service.
CVE-2026-47537[35]:
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the
| kernel mode layer where an attacker could cause an out-of-bounds
| write. A successful exploit of this vulnerability might lead to code
| execution, denial of service, escalation of privileges, information
| disclosure, and data tampering.
CVE-2026-47538[36]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the firmware where an attacker could cause an out-
| of-bounds write. A successful exploit of this vulnerability might
| lead to code execution, denial of service, escalation of privileges,
| information disclosure, and data tampering.
CVE-2026-47540[37]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode layer where an attacker could cause
| an integer underflow. A successful exploit of this vulnerability
| might lead to code execution, denial of service, escalation of
| privileges, information disclosure, and data tampering.
CVE-2026-47542[38]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode layer where an attacker could cause
| improper input validation. A successful exploit of this
| vulnerability might lead to code execution, denial of service,
| escalation of privileges, information disclosure, and data
| tampering.
CVE-2026-47543[39]:
| VIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode layer where an attacker could cause
| improper input validation. A successful exploit of this
| vulnerability might lead to code execution, denial of service,
| escalation of privileges, information disclosure, and data
| tampering.
CVE-2026-47545[40]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode layer where an attacker could cause
| an out-of-bounds read. A successful exploit of this vulnerability
| might lead to code execution, denial of service, escalation of
| privileges, information disclosure, and data tampering.
CVE-2026-47546[41]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the firmware where an attacker could cause improper
| input validation. A successful exploit of this vulnerability might
| lead to code execution, denial of service, escalation of privileges,
| information disclosure, and data tampering.
CVE-2026-47547[42]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the firmware where an attacker could cause improper
| input validation. A successful exploit of this vulnerability might
| lead to code execution, denial of service, escalation of privileges,
| information disclosure, and data tampering.
CVE-2026-47548[43]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode layer where an attacker could cause
| an out-of-bounds write. A successful exploit of this vulnerability
| might lead to code execution, denial of service, escalation of
| privileges, information disclosure, and data tampering.
CVE-2026-47549[44]:
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the
| kernel module where an unprivileged local user could cause a NULL
| pointer dereference. A successful exploit of this vulnerability
| might lead to denial of service.
CVE-2026-47551[45]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode layer where a user could cause a
| use-after-free. A successful exploit of this vulnerability might
| lead to code execution, denial of service, escalation of privileges,
| information disclosure, and data tampering.
CVE-2026-47552[46]:
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the
| kernel mode layer where an unprivileged user could bypass an
| authorization check and modify privileged configuration. A
| successful exploit of this vulnerability might lead to code
| execution, denial of service, escalation of privileges, information
| disclosure, and data tampering.
CVE-2026-47553[47]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode layer where an unprivileged user
| could cause an out-of-bounds write. A successful exploit of this
| vulnerability might lead to code execution, denial of service,
| escalation of privileges, information disclosure, and data
| tampering.
CVE-2026-47554[48]:
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the
| kernel mode layer where improper verification of cryptographic
| signatures may cause signature verification to be bypassed under
| memory pressure. A successful exploit of this vulnerability might
| lead to denial of service and data tampering.
CVE-2026-47555[49]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode layer where a user could cause
| uninitialized kernel memory to be copied back to userspace. A
| successful exploit of this vulnerability might lead to information
| disclosure.
CVE-2026-47556[50]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode layer where an unprivileged user
| could cause an integer overflow that leads to an out-of-bounds
| write. A successful exploit of this vulnerability might lead to code
| execution, denial of service, escalation of privileges, information
| disclosure, and data tampering.
CVE-2026-47557[51]:
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the
| kernel mode layer where an unprivileged user could cause a NULL
| pointer dereference. A successful exploit of this vulnerability
| might lead to denial of service.
CVE-2026-47558[52]:
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the
| kernel mode layer where an unprivileged user could cause a double-
| free of imported memory state. A successful exploit of this
| vulnerability might lead to code execution, denial of service,
| escalation of privileges, information disclosure, and data
| tampering.
CVE-2026-47559[53]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode layer, where a user could access
| memory belonging to another user's process. A successful exploit of
| this vulnerability might lead to code execution, escalation of
| privileges, data tampering, denial of service, and information
| disclosure.
CVE-2026-47560[54]:
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the
| kernel mode layer where an unprivileged user could cause a use-
| after-free. A successful exploit of this vulnerability might lead to
| code execution, denial of service, escalation of privileges,
| information disclosure, and data tampering.
CVE-2026-47561[55]:
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the
| kernel mode layer where the size of an ioctl input buffer is not
| validated, allowing an unprivileged caller to trigger an out-of-
| bounds write in kernel memory. A successful exploit of this
| vulnerability might lead to code execution, denial of service,
| escalation of privileges, information disclosure, and data
| tampering.
CVE-2026-47562[56]:
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the
| kernel mode layer where a user could inject crafted text into the
| kernel log because the supplied version string is not properly
| sanitized. A successful exploit of this vulnerability might lead to
| denial of service and data tampering.
CVE-2026-47563[57]:
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the
| kernel mode layer where a user could cause a NULL pointer
| dereference. A successful exploit of this vulnerability might lead
| to code execution, denial of service, escalation of privileges,
| information disclosure, and data tampering.
CVE-2026-47565[58]:
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the
| kernel mode layer where a privileged user could trigger a race
| condition that leads to an out-of-bounds write. A successful exploit
| of this vulnerability might lead to code execution, denial of
| service, escalation of privileges, information disclosure, and data
| tampering.
CVE-2026-47566[59]:
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the
| kernel mode layer where an unprivileged user could cause a memory
| leak in error paths leading to kernel memory exhaustion. A
| successful exploit of this vulnerability might lead to denial of
| service.
CVE-2026-47567[60]:
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the
| kernel mode layer, where a user could cause uncontrolled resource
| consumption by exhausting the DRM VMA offset address space. A
| successful exploit of this vulnerability might lead to denial of
| service.
CVE-2026-47568[61]:
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the
| kernel mode layer where a user could cause uncontrolled kernel log
| generation by repeatedly invoking an interface that emits unrate-
| limited error messages. A successful exploit of this vulnerability
| might lead to denial of service.
CVE-2026-47569[62]:
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the
| kernel mode layer where a user could cause a type confusion via a
| handle recycle race. A successful exploit of this vulnerability
| might lead to code execution, denial of service, escalation of
| privileges, information disclosure, and data tampering.
CVE-2026-47586[63]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel module where an attacker could cause a
| use-after-free. A successful exploit of this vulnerability might
| lead to code execution, denial of service, escalation of privileges,
| information disclosure, and data tampering.
CVE-2026-47587[64]:
| NVIDIA GPU Display Driver for Linux contains a vulnerability where
| an unprivileged user could cause a use-after-free. A successful
| exploit of this vulnerability might lead to code execution,
| escalation of privileges, denial of service, information disclosure,
| and data tampering.
CVE-2026-47588[65]:
| NVIDIA GPU Display Driver for Linux contains a vulnerability where
| an unprivileged user could cause a use-after-free condition by
| issuing a sequence of driver commands. A successful exploit of this
| vulnerability might lead to code execution, escalation of
| privileges, denial of service and information disclosure.
CVE-2026-47589[66]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability where an unprivileged user may cause a use-after-free
| condition by issuing a sequence of driver commands. A successful
| exploit of this vulnerability might lead to code execution,
| escalation of privileges, denial of service, and information
| disclosure.
CVE-2026-47590[67]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability where an unprivileged user may cause a use-after-free
| condition by issuing a sequence of driver commands. A successful
| exploit of this vulnerability might lead to code execution,
| escalation of privileges, denial of service, and information
| disclosure.
CVE-2026-47591[68]:
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the
| kernel mode layer where an unprivileged user could bypass read-only
| memory protection due to incorrect authorization, enabling write
| access to memory marked read-only. A successful exploit of this
| vulnerability might lead to code execution, denial of service,
| escalation of privileges, information disclosure, and data
| tampering.
CVE-2026-47592[69]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode layer where an unprivileged user
| could cause an out-of-bounds read. A successful exploit of this
| vulnerability might lead to code execution, denial of service,
| escalation of privileges, information disclosure, and data
| tampering.
CVE-2026-47594[70]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability where an unprivileged user may cause a use-after-free
| condition by issuing a sequence of driver commands. A successful
| exploit of this vulnerability might lead to code execution,
| escalation of privileges, denial of service, data tampering, and
| information disclosure.
CVE-2026-47595[71]:
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the
| kernel mode layer where an unprivileged user can write to read-only
| memory because the memory's permissions are not preserved. A
| successful exploit of this vulnerability might lead to code
| execution, escalation of privileges, denial of service, information
| disclosure, and data tampering.
CVE-2026-47596[72]:
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the
| kernel mode layer where an unprivileged user can write to read-only
| memory because the memory's permissions are not preserved. A
| successful exploit of this vulnerability might lead to code
| execution and escalation of privileges.
CVE-2026-47597[73]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the open-source kernel module Resource Server where
| an unprivileged local user could cause a use-after-free through a
| missing self-reference guard in the map cleanup path. A successful
| exploit of this vulnerability might lead to code execution,
| escalation of privileges, denial of service, information disclosure,
| and data tampering.
CVE-2026-47598[74]:
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the
| open-source kernel module event delivery path where an unprivileged
| local user could cause a use-after-free through a race between
| asynchronous event delivery and file close. A successful exploit of
| this vulnerability might lead to code execution, escalation of
| privileges, denial of service, information disclosure, and data
| tampering.
CVE-2026-47599[75]:
| NVIDIA GPU Display Driver for Linux contains a vulnerability in the
| open-source kernel module where an unprivileged local user could
| cause improper preservation of memory access permissions during DMA
| mapping. A successful exploit of this vulnerability might lead to
| code execution, escalation of privileges, denial of service,
| information disclosure, and data tampering.
CVE-2026-47600[76]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode layer where an error-handling path
| could operate on an improperly initialized resource. A successful
| exploit of this vulnerability might lead to code execution,
| escalation of privileges, denial of service, information disclosure,
| and data tampering.
CVE-2026-47601[77]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the open-source kernel module DMA-BUF import path
| where an unprivileged local user could cause improper preservation
| of memory access permissions when importing a read-only buffer from
| another device's DMA-BUF exporter. A successful exploit of this
| vulnerability might lead to code execution, escalation of
| privileges, denial of service, information disclosure, and data
| tampering.
CVE-2026-47602[78]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode driver where a local user can cause
| the driver to dereference an untrusted pointer. A successful exploit
| of this vulnerability might lead to denial of service and
| information disclosure.
CVE-2026-47603[79]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode driver where a local user may
| access another process's GPU channel state due to missing
| authorization checks. A successful exploit of this vulnerability
| might lead to information disclosure.
CVE-2026-47604[80]:
| NVIDIA GPU Display Driver for Windows and Linux contains a
| vulnerability in the kernel mode driver where a local user may
| access another process's GPU channel state due to missing
| authorization checks. A successful exploit of this vulnerability
| might lead to information disclosure.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-47489
https://www.cve.org/CVERecord?id=CVE-2026-47489
[1] https://security-tracker.debian.org/tracker/CVE-2026-47491
https://www.cve.org/CVERecord?id=CVE-2026-47491
[2] https://security-tracker.debian.org/tracker/CVE-2026-47492
https://www.cve.org/CVERecord?id=CVE-2026-47492
[3] https://security-tracker.debian.org/tracker/CVE-2026-47494
https://www.cve.org/CVERecord?id=CVE-2026-47494
[4] https://security-tracker.debian.org/tracker/CVE-2026-47496
https://www.cve.org/CVERecord?id=CVE-2026-47496
[5] https://security-tracker.debian.org/tracker/CVE-2026-47500
https://www.cve.org/CVERecord?id=CVE-2026-47500
[6] https://security-tracker.debian.org/tracker/CVE-2026-47501
https://www.cve.org/CVERecord?id=CVE-2026-47501
[7] https://security-tracker.debian.org/tracker/CVE-2026-47503
https://www.cve.org/CVERecord?id=CVE-2026-47503
[8] https://security-tracker.debian.org/tracker/CVE-2026-47504
https://www.cve.org/CVERecord?id=CVE-2026-47504
[9] https://security-tracker.debian.org/tracker/CVE-2026-47506
https://www.cve.org/CVERecord?id=CVE-2026-47506
[10] https://security-tracker.debian.org/tracker/CVE-2026-47507
https://www.cve.org/CVERecord?id=CVE-2026-47507
[11] https://security-tracker.debian.org/tracker/CVE-2026-47508
https://www.cve.org/CVERecord?id=CVE-2026-47508
[12] https://security-tracker.debian.org/tracker/CVE-2026-47509
https://www.cve.org/CVERecord?id=CVE-2026-47509
[13] https://security-tracker.debian.org/tracker/CVE-2026-47510
https://www.cve.org/CVERecord?id=CVE-2026-47510
[14] https://security-tracker.debian.org/tracker/CVE-2026-47511
https://www.cve.org/CVERecord?id=CVE-2026-47511
[15] https://security-tracker.debian.org/tracker/CVE-2026-47512
https://www.cve.org/CVERecord?id=CVE-2026-47512
[16] https://security-tracker.debian.org/tracker/CVE-2026-47513
https://www.cve.org/CVERecord?id=CVE-2026-47513
[17] https://security-tracker.debian.org/tracker/CVE-2026-47514
https://www.cve.org/CVERecord?id=CVE-2026-47514
[18] https://security-tracker.debian.org/tracker/CVE-2026-47515
https://www.cve.org/CVERecord?id=CVE-2026-47515
[19] https://security-tracker.debian.org/tracker/CVE-2026-47516
https://www.cve.org/CVERecord?id=CVE-2026-47516
[20] https://security-tracker.debian.org/tracker/CVE-2026-47517
https://www.cve.org/CVERecord?id=CVE-2026-47517
[21] https://security-tracker.debian.org/tracker/CVE-2026-47518
https://www.cve.org/CVERecord?id=CVE-2026-47518
[22] https://security-tracker.debian.org/tracker/CVE-2026-47522
https://www.cve.org/CVERecord?id=CVE-2026-47522
[23] https://security-tracker.debian.org/tracker/CVE-2026-47523
https://www.cve.org/CVERecord?id=CVE-2026-47523
[24] https://security-tracker.debian.org/tracker/CVE-2026-47524
https://www.cve.org/CVERecord?id=CVE-2026-47524
[25] https://security-tracker.debian.org/tracker/CVE-2026-47525
https://www.cve.org/CVERecord?id=CVE-2026-47525
[26] https://security-tracker.debian.org/tracker/CVE-2026-47526
https://www.cve.org/CVERecord?id=CVE-2026-47526
[27] https://security-tracker.debian.org/tracker/CVE-2026-47527
https://www.cve.org/CVERecord?id=CVE-2026-47527
[28] https://security-tracker.debian.org/tracker/CVE-2026-47528
https://www.cve.org/CVERecord?id=CVE-2026-47528
[29] https://security-tracker.debian.org/tracker/CVE-2026-47529
https://www.cve.org/CVERecord?id=CVE-2026-47529
[30] https://security-tracker.debian.org/tracker/CVE-2026-47530
https://www.cve.org/CVERecord?id=CVE-2026-47530
[31] https://security-tracker.debian.org/tracker/CVE-2026-47531
https://www.cve.org/CVERecord?id=CVE-2026-47531
[32] https://security-tracker.debian.org/tracker/CVE-2026-47532
https://www.cve.org/CVERecord?id=CVE-2026-47532
[33] https://security-tracker.debian.org/tracker/CVE-2026-47533
https://www.cve.org/CVERecord?id=CVE-2026-47533
[34] https://security-tracker.debian.org/tracker/CVE-2026-47534
https://www.cve.org/CVERecord?id=CVE-2026-47534
[35] https://security-tracker.debian.org/tracker/CVE-2026-47537
https://www.cve.org/CVERecord?id=CVE-2026-47537
[36] https://security-tracker.debian.org/tracker/CVE-2026-47538
https://www.cve.org/CVERecord?id=CVE-2026-47538
[37] https://security-tracker.debian.org/tracker/CVE-2026-47540
https://www.cve.org/CVERecord?id=CVE-2026-47540
[38] https://security-tracker.debian.org/tracker/CVE-2026-47542
https://www.cve.org/CVERecord?id=CVE-2026-47542
[39] https://security-tracker.debian.org/tracker/CVE-2026-47543
https://www.cve.org/CVERecord?id=CVE-2026-47543
[40] https://security-tracker.debian.org/tracker/CVE-2026-47545
https://www.cve.org/CVERecord?id=CVE-2026-47545
[41] https://security-tracker.debian.org/tracker/CVE-2026-47546
https://www.cve.org/CVERecord?id=CVE-2026-47546
[42] https://security-tracker.debian.org/tracker/CVE-2026-47547
https://www.cve.org/CVERecord?id=CVE-2026-47547
[43] https://security-tracker.debian.org/tracker/CVE-2026-47548
https://www.cve.org/CVERecord?id=CVE-2026-47548
[44] https://security-tracker.debian.org/tracker/CVE-2026-47549
https://www.cve.org/CVERecord?id=CVE-2026-47549
[45] https://security-tracker.debian.org/tracker/CVE-2026-47551
https://www.cve.org/CVERecord?id=CVE-2026-47551
[46] https://security-tracker.debian.org/tracker/CVE-2026-47552
https://www.cve.org/CVERecord?id=CVE-2026-47552
[47] https://security-tracker.debian.org/tracker/CVE-2026-47553
https://www.cve.org/CVERecord?id=CVE-2026-47553
[48] https://security-tracker.debian.org/tracker/CVE-2026-47554
https://www.cve.org/CVERecord?id=CVE-2026-47554
[49] https://security-tracker.debian.org/tracker/CVE-2026-47555
https://www.cve.org/CVERecord?id=CVE-2026-47555
[50] https://security-tracker.debian.org/tracker/CVE-2026-47556
https://www.cve.org/CVERecord?id=CVE-2026-47556
[51] https://security-tracker.debian.org/tracker/CVE-2026-47557
https://www.cve.org/CVERecord?id=CVE-2026-47557
[52] https://security-tracker.debian.org/tracker/CVE-2026-47558
https://www.cve.org/CVERecord?id=CVE-2026-47558
[53] https://security-tracker.debian.org/tracker/CVE-2026-47559
https://www.cve.org/CVERecord?id=CVE-2026-47559
[54] https://security-tracker.debian.org/tracker/CVE-2026-47560
https://www.cve.org/CVERecord?id=CVE-2026-47560
[55] https://security-tracker.debian.org/tracker/CVE-2026-47561
https://www.cve.org/CVERecord?id=CVE-2026-47561
[56] https://security-tracker.debian.org/tracker/CVE-2026-47562
https://www.cve.org/CVERecord?id=CVE-2026-47562
[57] https://security-tracker.debian.org/tracker/CVE-2026-47563
https://www.cve.org/CVERecord?id=CVE-2026-47563
[58] https://security-tracker.debian.org/tracker/CVE-2026-47565
https://www.cve.org/CVERecord?id=CVE-2026-47565
[59] https://security-tracker.debian.org/tracker/CVE-2026-47566
https://www.cve.org/CVERecord?id=CVE-2026-47566
[60] https://security-tracker.debian.org/tracker/CVE-2026-47567
https://www.cve.org/CVERecord?id=CVE-2026-47567
[61] https://security-tracker.debian.org/tracker/CVE-2026-47568
https://www.cve.org/CVERecord?id=CVE-2026-47568
[62] https://security-tracker.debian.org/tracker/CVE-2026-47569
https://www.cve.org/CVERecord?id=CVE-2026-47569
[63] https://security-tracker.debian.org/tracker/CVE-2026-47586
https://www.cve.org/CVERecord?id=CVE-2026-47586
[64] https://security-tracker.debian.org/tracker/CVE-2026-47587
https://www.cve.org/CVERecord?id=CVE-2026-47587
[65] https://security-tracker.debian.org/tracker/CVE-2026-47588
https://www.cve.org/CVERecord?id=CVE-2026-47588
[66] https://security-tracker.debian.org/tracker/CVE-2026-47589
https://www.cve.org/CVERecord?id=CVE-2026-47589
[67] https://security-tracker.debian.org/tracker/CVE-2026-47590
https://www.cve.org/CVERecord?id=CVE-2026-47590
[68] https://security-tracker.debian.org/tracker/CVE-2026-47591
https://www.cve.org/CVERecord?id=CVE-2026-47591
[69] https://security-tracker.debian.org/tracker/CVE-2026-47592
https://www.cve.org/CVERecord?id=CVE-2026-47592
[70] https://security-tracker.debian.org/tracker/CVE-2026-47594
https://www.cve.org/CVERecord?id=CVE-2026-47594
[71] https://security-tracker.debian.org/tracker/CVE-2026-47595
https://www.cve.org/CVERecord?id=CVE-2026-47595
[72] https://security-tracker.debian.org/tracker/CVE-2026-47596
https://www.cve.org/CVERecord?id=CVE-2026-47596
[73] https://security-tracker.debian.org/tracker/CVE-2026-47597
https://www.cve.org/CVERecord?id=CVE-2026-47597
[74] https://security-tracker.debian.org/tracker/CVE-2026-47598
https://www.cve.org/CVERecord?id=CVE-2026-47598
[75] https://security-tracker.debian.org/tracker/CVE-2026-47599
https://www.cve.org/CVERecord?id=CVE-2026-47599
[76] https://security-tracker.debian.org/tracker/CVE-2026-47600
https://www.cve.org/CVERecord?id=CVE-2026-47600
[77] https://security-tracker.debian.org/tracker/CVE-2026-47601
https://www.cve.org/CVERecord?id=CVE-2026-47601
[78] https://security-tracker.debian.org/tracker/CVE-2026-47602
https://www.cve.org/CVERecord?id=CVE-2026-47602
[79] https://security-tracker.debian.org/tracker/CVE-2026-47603
https://www.cve.org/CVERecord?id=CVE-2026-47603
[80] https://security-tracker.debian.org/tracker/CVE-2026-47604
https://www.cve.org/CVERecord?id=CVE-2026-47604
Please adjust the affected versions in the BTS as needed.
More information about the pkg-nvidia-devel
mailing list