NVIDIA vGPU Manager on Linux: out-of-bounds reads in the host kernel mode layer
Impact
An attacker can read outside buffer boundaries in the Virtual GPU Manager's kernel mode layer on the Linux hypervisor host. NVIDIA assigned four ids to this class in bulletin 2026/5861 (CVE-2026-47519, 47520, 47521, 47536) with the same score, the same advisory and the same fix, and the records contain no text that distinguishes the code paths. The practical effect is host kernel memory disclosure on a machine whose job is to keep tenant VMs apart, and the leaked pointers make the guest-triggered write bugs in the same bulletin easier to land.
Who can reach it
Local to the vGPU host, and the companion entries in this bulletin show the guest VM as the usual source. Assume a user in a guest VM with a vGPU assigned can reach it; no host credentials.
What to do
Update the Virtual GPU Manager on every Linux hypervisor host to the version in NVIDIA bulletin 2026/5861, which covers all four ids; the record gives no version number. Migrate or shut down each host's VMs and reboot it, rolling through the fleet.
Also covers 3 CVEs
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- NVIDIA vGPU Manager on Linux: out-of-bounds write in the host kernel mode layerCVE-2026-47541 · NVIDIA vGPU Virtual GPU Manager for Linux (kernel mode layer)High
- NVIDIA GPU firmware: access of an uninitialized pointer reachable from a local attackerCVE-2026-47528 · NVIDIA GPU firmware as shipped with the GPU Display Driver (uninitialized pointer access)High
- NVIDIA vGPU Manager on Linux: out-of-bounds read in GPU firmwareCVE-2026-47535 · NVIDIA vGPU Virtual GPU Manager for Linux (GPU firmware)High
- NVIDIA GPU driver: integer underflow in the kernel mode layerCVE-2026-47540 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer, size arithmetic)High
- NVIDIA Windows GPU driver: untrusted user pointer is dereferenced without validationCVE-2026-47550 · NVIDIA GPU Display Driver for Windows (kernel mode layer, pointer validation)High
- NVIDIA Linux GPU driver: unprivileged user bypasses an authorization check and changes privileged settingsCVE-2026-47552 · NVIDIA GPU Display Driver for Linux (kernel mode layer, privileged configuration)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.