GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA vGPU Manager on Linux: out-of-bounds read in GPU firmware

CVSS 7.8CVE-2026-47535NVIDIA / GPU stackcurated

Impact

The out-of-bounds read is in firmware running on the GPU rather than in host kernel code, so the disclosure happens in a context the hypervisor cannot inspect and host-level monitoring will not log. On a vGPU host the GPU firmware is the shared component underneath every tenant VM on the board, which makes a leak there a cross-tenant concern rather than a single-VM one. NVIDIA ships the firmware with the vGPU Manager package, so there is no separate flashing procedure, but the GPU does have to be reinitialized.

Who can reach it

Local to the vGPU host; in this bulletin the realistic source is a user in a guest VM with a vGPU assigned, reaching the GPU through the normal driver interface.

What to do

Install the Virtual GPU Manager package from NVIDIA bulletin 2026/5861, which carries the updated firmware; no fixed version appears in this record. The GPU must come up with the new firmware, so evacuate the host's VMs and reboot the host rather than restarting services.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.