{"id":"ECHO-7f4c-a6c7-4d4f","upstream":["CVE-2026-47601"],"severity":[],"modified":"2026-10-06T11:16:15.750Z","affected":[{"package":{"ecosystem":"Echo","name":"nvidia-graphics-drivers"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"590.48.01-0ubuntu1+e1"}]}]}],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-47601"},{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-47601"}],"withdrawn":"2026-10-06T11:16:15.750Z","summary":"Vulnerability is in the NVIDIA kernel-mode driver (nvidia.ko / open kernel module). Echo ships only the userspace\ncuda-compat libraries (libcuda, nvvm, ptxjitcompiler, ...) via the cuda-* packages; that\ncomponent is provided by the host, not the image.\nhttps://github.com/NVIDIA/product-security/tree/main/2026/5861\n"}