{"id":"CVE-2026-47558","title":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause a double-free of imported memory state","summary":"NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause a double-free of imported memory state. A successful exploit of this vulnerability might lead to code execution,…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-415","CWE-1341"],"vendor":"NVIDIA","product":"GeForce","affected":["GeForce All driver versions prior to 615.71.09","GeForce All driver versions prior to 610.57.04","rtx_quadro_nvs All driver versions prior to 615.71.09","rtx_quadro_nvs All driver versions prior to 610.57.04","rtx_quadro_nvs All driver versions prior to 595.91.07","rtx_quadro_nvs All driver versions prior to 580.178.04","Tesla All driver versions prior to 615.71.09","Tesla All driver versions prior to 610.57.04","Tesla All driver versions prior to 595.91.07","Tesla All driver versions prior to 580.178.04","GeForce All driver versions prior to 595.91.07","GeForce All driver versions prior to 580.178.04","guest_driver 595.71.05(All versions prior to and including vGPU 20.1)","guest_driver 580.159.03(All versions prior to and including vGPU 19.5)"],"published":"2026-09-30","updated":"2026-10-01","sourceUpdated":"2026-10-01T04:18:15.973","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-47558","references":[{"url":"https://github.com/NVIDIA/product-security/tree/main/2026/5861","label":"psirt@nvidia.com"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47558","label":"psirt@nvidia.com"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-47558","label":"psirt@nvidia.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-47558.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-47558"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2544102"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-30T17:50:50.249820Z"},"ingestedAt":"2026-09-30T16:10:07.533Z","epss":0.00186,"epssPercentile":0.07352,"slug":"CVE-2026-47558","body":"## Overview\n\nNVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause a double-free of imported memory state. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9 · updated 2026-09-30 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-47558.json)","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}