GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA vGPU Manager: crafted guest RPC message causes an out-of-bounds write in the GSP plugin

CVSS 7.8CVE-2026-47498NVIDIA / GPU stackcurated

Impact

The GSP plugin parses RPC messages sent by guest VMs and a crafted message overflows a buffer. The RPC path is the main control channel between a vGPU guest and the host plugin, so this is attacker-controlled data hitting host-side parsing code by design. For a GPU cloud running vGPU, a successful write here is a guest-to-host escalation that reaches every tenant on the board.

Who can reach it

From a guest VM with a vGPU assigned. Any user in that VM who can reach the GPU driver can emit the RPC; no host credentials.

What to do

Patch the Virtual GPU Manager on all hypervisor hosts per NVIDIA bulletin 2026/5861; no fixed version is listed in this record. Migrate or stop the host's VMs and reboot it; roll through the fleet host by host.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.