GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA vGPU Virtual GPU Manager: guest VM can trigger an out-of-bounds write in the host via crafted RPC

CVSS 7.3CVE-2026-47496NVIDIA / GPU stackcurated

Impact

A user inside a guest VM that has a vGPU attached can send a crafted RPC to the host-side vGPU plugin and corrupt host memory. On a multi-tenant vGPU host this is a guest-to-host boundary crossing: the plugin runs in the hypervisor host context, so successful exploitation means privilege escalation, data tampering, or taking down every vGPU guest sharing that physical GPU. NVIDIA rates it 7.3 and lists privilege escalation, data tampering and denial of service as outcomes. It is the highest-impact item in bulletin 5861 for anyone selling sliced GPUs.

Who can reach it

Any authenticated user inside a guest VM holding a vGPU device - no host access and no host credentials needed. Local to the guest, remote with respect to the host.

What to do

Install the fixed vGPU Virtual GPU Manager host driver from NVIDIA bulletin 2026/5861 and the matching guest driver branch. Updating the host vGPU manager requires evacuating or shutting down the vGPU guests on that host, unloading the kernel modules, and in practice draining and rebooting the node. The bulletin is the authority on the fixed branch versions; do not assume a point release.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.