GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA vGPU Virtual GPU Manager: incorrect numeric conversion in the kernel mode layer

CVSS 6.7CVE-2026-47539NVIDIA / GPU stackcurated

Impact

An incorrect numeric conversion in the host vGPU manager's kernel mode layer lets a privileged local caller drive the driver out of bounds, with code execution, privilege escalation, information disclosure, data tampering and denial of service listed. This is host-side code on a vGPU hypervisor, so a crash takes down every guest sharing the physical GPU, not one tenant. High privileges on the host are required, which puts it in the depth-in-depth category rather than the guest-escape category - unlike CVE-2026-47496 in the same bulletin.

Who can reach it

Local attacker with high privileges on the vGPU host (not inside a guest).

What to do

Update the vGPU Virtual GPU Manager to the fixed branch in NVIDIA bulletin 2026/5861. Evacuate the vGPU guests, drain the host and reboot to replace the kernel modules.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.