SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-16280

CRITICAL · CVSS 9.8 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

An integer overflow vulnerability in the calculation of physical offsets for sparse PMRs can lead to 32-bit truncation, affecting GPU memory management unit (MMU) mappings for PMRs larger than 4 GB. This flaw may allow non-privileged users to access unintended physical memory, potentially resulting in memory corruption or information disclosure. Organizations utilizing affected GPU hardware should prioritize patching this vulnerability due to its critical severity and potential impact on system integrity and data confidentiality.

CVE
CVE-2026-16280
Severity
CRITICAL
CVSS
9.8
EPSS
0.29%

Original NVD Description

An integer overflow when calculating physical offsets for sparse PMRs may result in 32-bit truncation of address computations for PMRs larger than 4 GB. This can lead to incorrect GPU MMU mappings and may allow a non-privileged user to trigger access to unintended physical memory, resulting in memory corruption or information disclosure.

Related CVEs

Other vulnerabilities affecting the same vendor(s)