CVE-2026-47562
Description
A flaw was found in the NVIDIA GPU Display Driver for Linux. The driver's kernel mode layer fails to properly sanitize user-supplied version strings, allowing a local user to inject crafted text into the kernel log. A successful exploit can lead to log data tampering and a Denial of Service (DoS).
Statement
This vulnerability is rated as Moderate severity because exploitation requires local system access with authenticated user privileges to pass crafted version strings to the kernel driver. While an unprivileged local user could manipulate or flood the kernel log buffer and potentially disrupt automated log monitoring systems, the flaw does not facilitate arbitrary code execution, privilege escalation to root, or unauthorized memory disclosure. The proprietary nvidia-driver package is an optional add-on component utilized primarily on systems equipped with dedicated NVIDIA GPU hardware, and standard installations utilizing default open-source display drivers remain unaffected.
Mitigation
If GPU hardware acceleration or compute capabilities are not required, prevent the NVIDIA kernel module from loading.
Create a configuration file to blacklist the module:
# echo "blacklist nvidia" > /etc/modprobe.d/disable-nvidia.conf
# echo "install nvidia /bin/true" >> /etc/modprobe.d/disable-nvidia.conf
If the module is already loaded, attempt to unload it:
# modprobe -r nvidia
Caveats:
Blacklisting the NVIDIA kernel module disables GPU hardware acceleration, which impacts graphical desktop sessions and prevents GPU compute workloads from functioning.
Warning:
Unloading the driver module while in use or restarting graphical services will terminate active user sessions. A system restart may be required to ensure dependent kernel modules are fully unloaded.
Common Vulnerability Scoring System (CVSS) Score Details
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
The following CVSS metrics and score provided are preliminary and subject to review.
CVSS v3 Score Breakdown
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| Base Score | 4.4 | N/A | 4.4 |
| Attack Vector | Local | N/A | Local |
| Attack Complexity | Low | N/A | Low |
| Privileges Required | Low | N/A | Low |
| User Interaction | None | N/A | None |
| Scope | Unchanged | N/A | Unchanged |
| Confidentiality | None | N/A | None |
| Integrity Impact | Low | N/A | Low |
| Availability Impact | Low | N/A | Low |
Vector
Red Hat: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
cve.org: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Understanding the Weakness (CWE)
Integrity,Confidentiality,Availability,Non-Repudiation
Technical Impact: Modify Application Data; Hide Activities; Execute Unauthorized Code or Commands
Interpretation of the log files may be hindered or misdirected if an attacker can supply data to the application that is subsequently logged verbatim. In the most benign case, an attacker may be able to insert false entries into the log file by providing the application with input that includes appropriate characters. Forged or otherwise corrupted log files can be used to cover an attacker's tracks, possibly by skewing statistics, or even to implicate another party in the commission of a malicious act. If the log file is processed automatically, the attacker can render the file unusable by corrupting the format of the file or injecting unexpected characters. An attacker may inject code or other commands into the log file and take advantage of a vulnerability in the log processing utility.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.