VYPR
Vypr IntelligenceAI-generatedSep 30, 2026· 25 CVEs

NVIDIA GPU Driver: 25 Vulnerabilities Disclosed, Ranging from Info Disclosure to Code Execution

NVIDIA disclosed 25 vulnerabilities in its GPU Display Driver for Windows and Linux on September 30, 2026, with potential impacts including code execution and privilege escalation.

Key findings

  • NVIDIA disclosed 25 vulnerabilities in its GPU Display Driver on September 30, 2026.
  • Flaws include missing authorization, memory corruption, and improper access controls in kernel mode drivers.
  • Potential impacts range from information disclosure to code execution and privilege escalation.
  • All vulnerabilities require local access to exploit.
  • NVIDIA has released updated drivers; users should update immediately.

On September 30, 2026, NVIDIA disclosed a significant batch of 25 vulnerabilities affecting its GPU Display Driver for Windows and Linux. These vulnerabilities, all disclosed on the same day, primarily stem from issues within the kernel mode driver and open-source kernel modules. The flaws present a range of risks, including information disclosure, denial of service, escalation of privileges, and potentially code execution.

Several vulnerabilities are related to improper authorization checks and memory access control. CVE-2026-47604 and CVE-2026-47603, both rated Medium, involve missing authorization checks in the kernel mode driver, allowing a local user to access another process's GPU channel state, leading to information disclosure. Similarly, CVE-2026-47591, a High severity vulnerability, describes how an unprivileged local user could bypass read-only memory protection due to incorrect authorization, enabling write access to memory marked read-only.

A notable theme among the High severity vulnerabilities is the potential for code execution and privilege escalation through memory corruption. CVE-2026-47600, CVE-2026-47599, CVE-2026-47598, CVE-2026-47597, CVE-2026-47595, CVE-2026-47594, CVE-2026-47593, CVE-2026-47590, CVE-2026-47589, CVE-2026-47588, CVE-2026-47587, CVE-2026-47586, CVE-2026-47585, CVE-2026-47583, and CVE-2026-47582 all describe scenarios involving use-after-free conditions, out-of-bounds writes, or improper preservation of memory access permissions. These memory safety issues can be triggered by local users through various means, including issuing specific driver commands or interacting with DMA-BUF import paths.

Other vulnerabilities include denial of service through NULL pointer dereferences (CVE-2026-47584) and improper locking (CVE-2026-47581), both rated Medium. CVE-2026-47580, a High severity flaw, involves a missing authorization issue that could lead to information disclosure and data tampering. CVE-2026-47602, also High, allows a local user to cause the driver to dereference an untrusted pointer, potentially leading to denial of service and information disclosure.

NVIDIA has released updated drivers to address these vulnerabilities. Users are strongly advised to update to the latest versions to mitigate the risks associated with these security flaws. Specific version information for the patches can be found in NVIDIA's security advisories.

This extensive batch of vulnerabilities underscores the importance of timely patching and vigilant security practices for users of NVIDIA products. The potential for local privilege escalation and code execution means that unpatched systems could be vulnerable to significant compromise. Users should consult NVIDIA's official security bulletins for detailed information on affected products and remediation steps.

AI-written article. Grounded in 25 CVE records listed below.