CVE-2026-47562
Awaiting Analysis Awaiting Analysis - Queue

Kernel Log Injection in NVIDIA GPU Display Driver for Linux

Vulnerability report for CVE-2026-47562, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: NVIDIA Corporation

Description

NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where a user could inject crafted text into the kernel log because the supplied version string is not properly sanitized. A successful exploit of this vulnerability might lead to denial of service and data tampering.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
nvidia gpu_display_driver *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-116 The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in NVIDIA GPU Display Driver for Linux where a user can inject crafted text into the kernel log due to improper sanitization of the version string. This could allow an attacker to manipulate logs or cause issues in the system.

Detection Guidance

This vulnerability involves improper sanitization of version strings in NVIDIA GPU Display Driver for Linux. Detection requires checking the installed driver version and logs for crafted text injection. Review kernel logs for unusual entries and verify driver version against NVIDIA's advisories. No specific commands are provided in the context.

Impact Analysis

The vulnerability might lead to denial of service, where the system becomes unresponsive, and data tampering, where unauthorized changes to data occur. It requires local access and could affect system stability and integrity.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling data tampering and denial of service through crafted text injection in kernel logs. Unauthorized modifications to logs may violate integrity requirements under these regulations.

Mitigation Strategies

Update the NVIDIA GPU Display Driver for Linux to the latest version provided by NVIDIA to address the improperly sanitized version string issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-47562. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart