NVIDIA vGPU Manager on Linux: out-of-bounds write in the host kernel mode layer
Impact
An attacker can write past a buffer in the Virtual GPU Manager's kernel mode layer on a Linux hypervisor host. A kernel write on a vGPU host is the worst outcome in this bulletin's vGPU set, because the host is what separates tenant VMs sharing one physical GPU. Pair it with the out-of-bounds reads in the same release and an attacker has both halves of a workable chain on an unpatched host.
Who can reach it
Local to the vGPU host; the companion vGPU entries in this bulletin show guest VM users as the reachable attacker, needing no host credentials.
What to do
Update the Virtual GPU Manager on each Linux hypervisor host per NVIDIA bulletin 2026/5861; the record states no fixed version. Migrate or stop every VM on the host and reboot it to install. Prioritize hosts carrying VMs from more than one customer.
References
Related entries
- NVIDIA vGPU Manager on Linux: out-of-bounds reads in the host kernel mode layerCVE-2026-47519 · NVIDIA vGPU Virtual GPU Manager for Linux (kernel mode layer)High
- NVIDIA Windows GPU driver: untrusted user pointer is dereferenced without validationCVE-2026-47550 · NVIDIA GPU Display Driver for Windows (kernel mode layer, pointer validation)High
- NVIDIA Linux GPU driver: unprivileged user bypasses an authorization check and changes privileged settingsCVE-2026-47552 · NVIDIA GPU Display Driver for Linux (kernel mode layer, privileged configuration)High
- NVIDIA Linux GPU driver: double-free of imported memory state in the kernel moduleCVE-2026-47558 · NVIDIA GPU Display Driver for Linux (kernel mode layer, imported memory state)High
- NVIDIA GPU driver: a user can access memory belonging to another user's processCVE-2026-47559 · NVIDIA GPU Display Driver for Windows and Linux (kernel mode layer, process memory isolation)High
- NVIDIA Linux GPU driver: unprivileged user triggers use-after-free in the kernel moduleCVE-2026-47560 · NVIDIA GPU Display Driver for Linux (kernel mode layer, object lifetime)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.