OSG-SEC-2026-09-30 NVIDIA Linux GPU Driver Security Vulnerabilities
Dear OSG Security Contacts,
NVIDIA has released a security update addressing multiple vulnerabilities in the NVIDIA Linux GPU driver and related kernel-mode components [1]. Several of these vulnerabilities can be triggered by an unprivileged local user and may result in code execution, privilege escalation, information disclosure, data tampering, or denial of service.
These vulnerabilities are relevant to OSG sites operating shared NVIDIA GPU worker nodes. Applicability depends on the NVIDIA driver branch and version installed on the worker node.
GPU compute jobs do not require an X11 or Wayland display server; however, GPU-enabled jobs may interact with the host NVIDIA kernel driver through NVIDIA GPU device interfaces.
IMPACTED VERSIONS:
Applicability is based on the NVIDIA Linux driver branch and version installed on the worker node.
The following NVIDIA Linux driver versions are affected:
R615: versions prior to 615.71.09
R610: versions prior to 610.57.04
R595: versions prior to 595.91.07
R580: versions prior to 580.178.04
The GPU model alone does not determine whether a worker is affected. Sites should verify the installed NVIDIA driver version on each GPU worker.
WHAT ARE THE VULNERABILITIES:
The NVIDIA bulletin addresses multiple vulnerabilities in the NVIDIA Linux kernel-mode driver and related components, including use-after-free, out-of-bounds reads and writes, type confusion, race conditions, authorization flaws, and memory-management issues.
For multiple vulnerabilities, NVIDIA identifies a local, low-privilege attack requiring no user interaction. Depending on the vulnerability, successful exploitation may result in:
- Code execution in kernel context.
- Escalation of privileges.
- Information disclosure.
- Data tampering.
- Denial of service.
WHAT YOU SHOULD DO:
OSG sites operating NVIDIA GPU worker nodes should:
- Identify the NVIDIA driver version installed on each GPU worker.
- Upgrade affected NVIDIA drivers to the corresponding fixed release or later.
- Reboot affected worker nodes as required to ensure the updated NVIDIA kernel modules are loaded.
Administrators can check the installed NVIDIA driver version with [2] : nvidia-smi --query-gpu=driver_version --format=csv,noheader
REFERENCES
[1] https://nvidia.custhelp.com/app/answers/detail/a_id/5861
[2] https://docs.nvidia.com/deploy/nvidia-smi/index.html
[3] https://portal.osg-htc.org/documentation/htc_workloads/specific_resource/gpu-jobs/
Please contact the OSG security team at [email protected] if you have any questions or concerns. OSG Security Team