NVIDIA GDD Kernel Module Priv Escalation via DMA Mapping
CVE-2026-47599 Published on September 30, 2026
NVIDIA GPU Display Driver for Linux contains a vulnerability in the open-source kernel module where an unprivileged local user could cause improper preservation of memory access permissions during DMA mapping. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.
Vulnerability Analysis
CVE-2026-47599 can be exploited with local system access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
Improper Preservation of Permissions
The software does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.
Products Associated with CVE-2026-47599
stack.watch emails you whenever new vulnerabilities are published in NVIDIA Geforce or NVIDIA Tesla. Just hit a watch button to start following.
Affected Versions
NVIDIA GeForce:- Version All driver versions prior to 615.71.09 is affected.
- Version All driver versions prior to 610.57.04 is affected.
- Version All driver versions prior to 615.71.09 is affected.
- Version All driver versions prior to 610.57.04 is affected.
- Version All driver versions prior to 595.91.07 is affected.
- Version All driver versions prior to 580.178.04 is affected.
- Version All driver versions prior to 615.71.09 is affected.
- Version All driver versions prior to 610.57.04 is affected.
- Version All driver versions prior to 595.91.07 is affected.
- Version All driver versions prior to 580.178.04 is affected.
- Version All driver versions prior to 595.91.07 is affected.
- Version All driver versions prior to 580.178.04 is affected.