GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA vGPU: a guest can reach privileged host GPU resources it is not authorized for

CVSS 7.8CVE-2026-47493NVIDIA / GPU stackcurated

Impact

A guest VM reaches host GPU resources that should be off limits to it, which is a direct break of the boundary vGPU exists to enforce. For a provider selling vGPU slices, that boundary is the product: a tenant VM touching host-side resources can affect or observe the GPU state of other VMs on the same physical board. The host has to be patched for this, not just the guest, so the maintenance falls on the hypervisor fleet.

Who can reach it

From inside a guest VM with a vGPU assigned. Authenticated as a normal user of that VM; no host credentials are needed.

What to do

Update the Virtual GPU Manager on every hypervisor host to the version NVIDIA lists in bulletin 2026/5861; the record gives no version number. Updating the vGPU Manager means migrating or shutting down every VM on the host and rebooting it, so plan this as a rolling host-by-host drain across the vGPU fleet.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.