GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA vGPU Manager on Linux: out-of-bounds write in the host kernel mode layer

CVSS 7.8CVE-2026-47541NVIDIA / GPU stackcurated

Impact

An attacker can write past a buffer in the Virtual GPU Manager's kernel mode layer on a Linux hypervisor host. A kernel write on a vGPU host is the worst outcome in this bulletin's vGPU set, because the host is what separates tenant VMs sharing one physical GPU. Pair it with the out-of-bounds reads in the same release and an attacker has both halves of a workable chain on an unpatched host.

Who can reach it

Local to the vGPU host; the companion vGPU entries in this bulletin show guest VM users as the reachable attacker, needing no host credentials.

What to do

Update the Virtual GPU Manager on each Linux hypervisor host per NVIDIA bulletin 2026/5861; the record states no fixed version. Migrate or stop every VM on the host and reboot it to install. Prioritize hosts carrying VMs from more than one customer.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.