CVE-2026-47601
Last modified
CVE-2026-47601 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the open-source kernel module DMA-BUF import path where an unprivileged local user could cause improper preservation of memory access permissions when importing a read-only buffer from another device's DMA-BUF exporter. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering..
Description
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the open-source kernel module DMA-BUF import path where an unprivileged local user could cause improper preservation of memory access permissions when importing a read-only buffer from another device's DMA-BUF exporter. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| NVIDIA | GeForce | All driver versions prior to 610.60 |
| NVIDIA | RTX, Quadro, NVS | All driver versions prior to 610.88 |
| NVIDIA | GeForce | All driver versions prior to 616.56 |
| NVIDIA | RTX, Quadro, NVS | All driver versions prior to 616.92 |
| NVIDIA | GeForce | All driver versions prior to 582.78 Only GPUs based on the NVIDIA Maxwell, Volta, and Pascal GPU architectures are affected. |
| NVIDIA | RTX, Quadro, NVS | All driver versions prior to 582.78 |
| NVIDIA | RTX, Quadro, NVS | All driver versions prior to 596.86 |
| NVIDIA | Tesla | All driver versions prior to 596.86 |
| NVIDIA | Tesla | All driver versions prior to 616.92 |
| NVIDIA | Tesla | All driver versions prior to 610.88 |
| NVIDIA | GeForce | All driver versions prior to 615.71.09 |
| NVIDIA | GeForce | All driver versions prior to 610.57.04 |
| NVIDIA | RTX, Quadro, NVS | All driver versions prior to 615.71.09 |
| NVIDIA | RTX, Quadro, NVS | All driver versions prior to 610.57.04 |
| NVIDIA | RTX, Quadro, NVS | All driver versions prior to 595.91.07 |
| NVIDIA | RTX, Quadro, NVS | All driver versions prior to 580.178.04 |
| NVIDIA | Tesla | All driver versions prior to 615.71.09 |
| NVIDIA | Tesla | All driver versions prior to 610.57.04 |
| NVIDIA | Tesla | All driver versions prior to 595.91.07 |
| NVIDIA | Tesla | All driver versions prior to 580.178.04 |
| NVIDIA | GeForce | All driver versions prior to 595.91.07 |
| NVIDIA | GeForce | All driver versions prior to 580.178.04 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-47601?
How severe is CVE-2026-47601?
How do I fix CVE-2026-47601?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-47596NVIDIA GPU Display Driver for Linux contains a vulnerability…7
- CVE-2026-47597NVIDIA GPU Display Driver for Windows and Linux contains a v…7.8
- CVE-2026-47598NVIDIA GPU Display Driver for Linux contains a vulnerability…7
- CVE-2026-47599NVIDIA GPU Display Driver for Linux contains a vulnerability…7.8
- CVE-2026-4760From Panorama Web HMI, an attacker can gain read access to c…7.7
- CVE-2026-47600NVIDIA GPU Display Driver for Windows and Linux contains a v…7.8
- CVE-2026-47602NVIDIA GPU Display Driver for Windows and Linux contains a v…7.1
- CVE-2026-47603NVIDIA GPU Display Driver for Windows and Linux contains a v…5.5
- CVE-2026-47604NVIDIA GPU Display Driver for Windows and Linux contains a v…5.5
- CVE-2026-47606NVIDIA Triton Inference Server for Linux contains a vulnerab…9.1
- CVE-2026-4761When a certificate and its private key are installed in the …7.5
- CVE-2026-47612NVIDIA Dynamo for Linux contains a vulnerability in the imag…7.5
Are you affected by CVE-2026-47601?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
