NVIDIA vGPU Manager: guest-triggered integer overflow leads to memory corruption
Impact
A guest user supplies values that overflow a size calculation in the kernel mode layer, and the resulting mismatch corrupts memory. Because the guest chooses the arithmetic, the corruption is steerable rather than random. On a vGPU host this is corruption in host context driven from a tenant VM, so it belongs in the same escape-candidate bucket as the other guest-reachable writes in bulletin 2026/5861.
Who can reach it
From inside a guest VM with a vGPU assigned, as an ordinary user of that VM.
What to do
Apply the Virtual GPU Manager update from NVIDIA bulletin 2026/5861 on each hypervisor host; the record names no fixed version. Installing it requires draining the host's VMs and rebooting.
References
Related entries
- NVIDIA vGPU plugin: guest RPC with an invalid performance state list size causes an out-of-bounds writeCVE-2026-47503 · NVIDIA Virtual GPU Manager (vGPU plugin, performance state list RPC)High
- NVIDIA Linux driver NGX updater: outdated embedded crypto library is vulnerable to type confusionCVE-2026-47504 · NVIDIA Linux GPU Display Driver (NGX updater, embedded cryptographic library)High
- NVIDIA Windows GPU driver: use-after-free in the kernel mode layerCVE-2026-47505 · NVIDIA GPU Display Driver for Windows (kernel mode layer)High
- NVIDIA GPU driver: out-of-bounds array access in the kernel mode layerCVE-2026-47507 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer, array indexing)High
- NVIDIA GPU driver: incorrect conversion between numeric types in the kernel mode layerCVE-2026-47508 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer, numeric conversion)High
- NVIDIA GPU driver: integer overflow in size arithmetic leads to an out-of-bounds writeCVE-2026-47510 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer, size arithmetic)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.