{"id":"CVE-2026-47504","title":"NVIDIA Linux GPU Display Driver contains a vulnerability in the NGX updater where an outdated embedded cryptographic library is susceptible to type confusion","summary":"NVIDIA Linux GPU Display Driver contains a vulnerability in the NGX updater where an outdated embedded cryptographic library is susceptible to type confusion. A successful exploit of this vulnerability might lead to code execution, denia…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-843"],"vendor":"NVIDIA","product":"GeForce","affected":["GeForce All driver versions prior to 615.71.09","GeForce All driver versions prior to 610.57.04","rtx_quadro_nvs All driver versions prior to 615.71.09","rtx_quadro_nvs All driver versions prior to 610.57.04","rtx_quadro_nvs All driver versions prior to 595.91.07","rtx_quadro_nvs All driver versions prior to 580.178.04","Tesla All driver versions prior to 615.71.09","Tesla All driver versions prior to 610.57.04","Tesla All driver versions prior to 595.91.07","Tesla All driver versions prior to 580.178.04","GeForce All driver versions prior to 595.91.07","GeForce All driver versions prior to 580.178.04"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T18:18:20.837","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-47504","references":[{"url":"https://github.com/NVIDIA/product-security/tree/main/2026/5861","label":"psirt@nvidia.com"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47504","label":"psirt@nvidia.com"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-47504","label":"psirt@nvidia.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-30T17:51:40.737833Z"},"ingestedAt":"2026-09-30T16:10:07.615Z","slug":"CVE-2026-47504","body":"## Overview\n\nNVIDIA Linux GPU Display Driver contains a vulnerability in the NGX updater where an outdated embedded cryptographic library is susceptible to type confusion. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, or data tampering.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}