{"id":"ECHO-7f4c-a6c7-4d4f","summary":"Vulnerability is in the NVIDIA kernel-mode driver (nvidia.ko / open kernel module). Echo ships only the userspace\ncuda-compat libraries (libcuda, nvvm, ptxjitcompiler, ...) via the cuda-* packages; that\ncomponent is provided by the host, not the image.\nhttps://github.com/NVIDIA/product-security/tree/main/2026/5861\n","modified":"2026-10-06T11:45:08.004094320Z","published":"2026-10-01T20:54:33.320Z","withdrawn":"2026-10-06T11:16:15.750Z","upstream":["CVE-2026-47601"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-47601"},{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-47601"}],"affected":[{"package":{"name":"nvidia-graphics-drivers","ecosystem":"Echo","purl":"pkg:deb/echo/nvidia-graphics-drivers"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"590.48.01-0ubuntu1+e1"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-7f4c-a6c7-4d4f.json"}}],"schema_version":"1.9.0"}