Tech5 min read

NVIDIA GPU Driver & vGPU Security Update: 114 CVEs and Fixed Versions

IkesanContents

TL;DR

What happened NVIDIA patched 114 vulnerabilities across GPU display drivers (Windows and Linux) and vGPU software, resolving risks of arbitrary code execution and privilege escalation.

What to do

  1. Windows GeForce: Update to 616.56 (R615), 610.88 (R610), or 582.78 (R580) or later
  2. Linux GeForce & vGPU: Apply branch-specific fixed releases detailed below

On September 30, 2026, NVIDIA published security bulletins addressing GPU display drivers and vGPU software.
Desktop users need to update their GeForce display drivers, while enterprise administrators running virtual machines on hypervisors must update their vGPU software stack.

According to the official GitHub security bulletin, 114 vulnerabilities were disclosed across multiple products and operating systems. The exact CVEs affecting your setup depend on the installed software. Successful exploitation could lead to arbitrary code execution, privilege escalation, data tampering, denial of service, or information disclosure.

Checking Your Current Driver Version

If the NVIDIA management tool nvidia-smi is installed on your system, run the following command in PowerShell, Command Prompt, or a Linux terminal to inspect your GPU model and driver version:
Details on query options are documented in the NVIDIA nvidia-smi documentation.

nvidia-smi --query-gpu=name,driver_version --format=csv,noheader

The command outputs the GPU model and current driver version:

NVIDIA GeForce RTX 4060, 616.56

On Windows, GeForce drivers can be updated directly through the NVIDIA app.
If downloading installers manually from the official driver download page, match your GPU and OS, and verify that the version meets or exceeds the fixed release for your branch.

After updating, rerun the command to confirm that the new driver version is active.

Fixed Versions for Windows GeForce

NVIDIA driver branches are release series such as R615 or R610. For instance, version 616.56 belongs to the R615 branch. The official advisory lists specific fixed versions for each Common Vulnerabilities and Exposures (CVE) identifier.

For Windows GeForce users, the minimum safe version depends on which driver branch is currently installed:

GeForce BranchFixed Version
R615616.56 or later
R610610.88 or later
R580582.78 or later (legacy architectures: Maxwell, Volta, Pascal)

Within the R610 branch, some CVEs were addressed in version 610.60. However, other vulnerabilities require version 610.88. Systems must run 610.88 or higher to resolve all disclosed issues.

Workstation and enterprise GPUs (such as NVIDIA RTX, Quadro, NVS, and Tesla) follow separate release schedules in the official security updates table. For example, Windows systems running NVIDIA RTX on the R615 branch require version 616.92.

Linux GeForce Driver Releases

Linux GeForce drivers use a dedicated versioning scheme. The fixed releases per branch are:

GeForce BranchFixed Version
R615615.71.09 or later
R610610.57.04 or later
R595595.91.07 or later
R580580.178.04 or later

vGPU Deployments and Virtual Machines

For NVIDIA vGPU deployments, the fixed releases are version 19.6 for the 19.x series and version 20.2 for the 20.x series.
Both the Virtual GPU Manager running on the hypervisor host and the guest drivers running inside individual virtual machines require updates.

The following versions apply to XenServer, VMware vSphere, Red Hat Enterprise Linux KVM, and Ubuntu hypervisors:

ComponentvGPU 19.6vGPU 20.2
Virtual GPU Manager580.178.05595.91.04
Linux Guest Driver580.178.04595.91.07
Windows Guest Driver582.78596.86

For host environments running Azure Local or Windows Server, refer to the official security bulletin for corresponding Virtual GPU Manager versions.

Severity Breakdown of the 114 Vulnerabilities

According to the CVSS (Common Vulnerability Scoring System) base metrics published in NVIDIA’s official JSON data as of October 1, 2026, the 114 CVEs break down into 78 High-severity issues and 36 Medium-severity issues.

Top 4 Vulnerabilities and Local Attack Requirements

Among the 114 disclosed flaws, the following four issues received the highest CVSS v3.1 base score of 7.8 (High):

CVEAffected ComponentDescription
CVE-2026-47505Windows GPU Display DriverRe-accessing freed memory within OS kernel space
CVE-2026-47500Windows & Linux GPU Display DriverImproper reference count cleanup leading to access of freed memory
CVE-2026-47489Linux GPU Display DriverRisk of read-only memory permissions being unexpectedly overwritten
CVE-2026-47574Linux vGPU Virtual GPU ManagerResources improperly transferred across distinct management boundaries

The top two issues are use-after-free flaws, where software continues to access memory addresses after they have been released. This can corrupt data written by other processes or crash the system.

All four vulnerabilities carry CVSS metrics specifying AV:L (Attack Vector: Local) and PR:L (Privileges Required: Low).
These flaws cannot be exploited directly over an untrusted network without prior access. Instead, an attacker must already have local execution privileges (such as basic unprivileged user access or the ability to run untrusted code on the target machine). Once executed locally, an attacker could exploit these bugs to escalate privileges to full administrative or root level.

Under the CVSS specification, authenticated remote sessions (such as SSH access) are classified as local attacks because the attacker operates code directly within the target OS environment.