GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA vGPU Manager: crafted data in the GSP tracing shared buffer causes improper access

CVSS 7.8CVE-2026-47497NVIDIA / GPU stackcurated

Impact

A guest VM user writes crafted data into a buffer shared with the GPU System Processor tracing component and causes improper access on the host side. GSP runs firmware on the GPU itself, below the hypervisor, so a flaw reached through it sits underneath the usual host defences. The shared buffer is a standing guest-to-host channel, which means this is reachable during normal operation rather than only in some unusual configuration.

Who can reach it

From inside a guest VM with a vGPU assigned, as a normal user of that VM.

What to do

Update the Virtual GPU Manager on every affected hypervisor host as directed by NVIDIA bulletin 2026/5861; the record gives no fixed version. This requires evacuating the host's VMs and rebooting it. If GSP tracing can be disabled in your deployment, check the bulletin for whether NVIDIA offers that as an interim mitigation rather than assuming it.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.