NVIDIA vGPU Manager: crafted guest RPC message causes an out-of-bounds write in the GSP plugin
Impact
The GSP plugin parses RPC messages sent by guest VMs and a crafted message overflows a buffer. The RPC path is the main control channel between a vGPU guest and the host plugin, so this is attacker-controlled data hitting host-side parsing code by design. For a GPU cloud running vGPU, a successful write here is a guest-to-host escalation that reaches every tenant on the board.
Who can reach it
From a guest VM with a vGPU assigned. Any user in that VM who can reach the GPU driver can emit the RPC; no host credentials.
What to do
Patch the Virtual GPU Manager on all hypervisor hosts per NVIDIA bulletin 2026/5861; no fixed version is listed in this record. Migrate or stop the host's VMs and reboot it; roll through the fleet host by host.
References
Related entries
- NVIDIA vGPU Manager: guest-triggered out-of-bounds read in the host kernel mode layerCVE-2026-47499 · NVIDIA vGPU Virtual GPU Manager (kernel mode layer)High
- NVIDIA GPU driver: use-after-free reachable by an unprivileged user through ordinary driver callsCVE-2026-47500 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer, object lifetime and refcounting)High
- NVIDIA Linux GPU driver: mismatched buffers during event buffer setup cause a kernel out-of-bounds writeCVE-2026-47501 · NVIDIA GPU Display Driver for Linux (kernel mode layer, event buffer setup)High
- NVIDIA vGPU Manager: guest-triggered integer overflow leads to memory corruptionCVE-2026-47502 · NVIDIA vGPU Virtual GPU Manager (kernel mode layer, size arithmetic)High
- NVIDIA vGPU plugin: guest RPC with an invalid performance state list size causes an out-of-bounds writeCVE-2026-47503 · NVIDIA Virtual GPU Manager (vGPU plugin, performance state list RPC)High
- NVIDIA Linux driver NGX updater: outdated embedded crypto library is vulnerable to type confusionCVE-2026-47504 · NVIDIA Linux GPU Display Driver (NGX updater, embedded cryptographic library)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.