{"id":"CVE-2026-47597","title":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the open-source kernel module Resource Server where an unprivileged local user could cause a use-after-free through a missing self-reference guard in the map cle…","summary":"NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the open-source kernel module Resource Server where an unprivileged local user could cause a use-after-free through a missing self-reference guard in the map cle…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-416"],"vendor":"NVIDIA","product":"GeForce","affected":["GeForce All driver versions prior to 610.60","rtx_quadro_nvs All driver versions prior to 610.88","GeForce All driver versions prior to 616.56","rtx_quadro_nvs All driver versions prior to  616.92","GeForce All driver versions prior to 582.78 Only GPUs based on the NVIDIA Maxwell, Volta, and Pascal GPU architectures are affected.","rtx_quadro_nvs All driver versions prior to 582.78","rtx_quadro_nvs All driver versions prior to 596.86","Tesla All driver versions prior to 596.86","Tesla All driver versions prior to 596.86","Tesla All driver versions prior to 616.92","Tesla All driver versions prior to 610.88","GeForce All driver versions prior to 615.71.09","GeForce All driver versions prior to 610.57.04","rtx_quadro_nvs All driver versions prior to 615.71.09","rtx_quadro_nvs All driver versions prior to 610.57.04","rtx_quadro_nvs All driver versions prior to 595.91.07","rtx_quadro_nvs All driver versions prior to 580.178.04","Tesla All driver versions prior to 615.71.09","Tesla All driver versions prior to 610.57.04","Tesla All driver versions prior to 595.91.07","Tesla All driver versions prior to 580.178.04","GeForce All driver versions prior to 595.91.07","GeForce All driver versions prior to 580.178.04","guest_driver 595.71.05(All versions prior to and including vGPU 20.1)","guest_driver 580.159.03(All versions prior to and including vGPU 19.5)"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T18:18:35.810","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-47597","references":[{"url":"https://github.com/NVIDIA/product-security/tree/main/2026/5861","label":"psirt@nvidia.com"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47597","label":"psirt@nvidia.com"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-47597","label":"psirt@nvidia.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-30T17:20:33.171794Z"},"ingestedAt":"2026-09-30T16:10:07.462Z","slug":"CVE-2026-47597","body":"## Overview\n\nNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the open-source kernel module Resource Server where an unprivileged local user could cause a use-after-free through a missing self-reference guard in the map cleanup path. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure, and data tampering.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}