NVIDIA vGPU Virtual GPU Manager: out-of-bounds read in the kernel mode layer
Impact
The host vGPU manager reads outside allocated bounds when handling input from a privileged local caller, leaking host kernel memory or faulting the driver. On a vGPU host the fault is multi-tenant: the physical GPU and all guests slicing it go with it, and recovering means a reboot of a node whose guests have to be moved first. NVIDIA requires high privileges on the host, so this is not reachable from inside a guest.
Who can reach it
Local attacker with high privileges on the Linux vGPU host.
What to do
Update the vGPU Virtual GPU Manager to the fixed branch in NVIDIA bulletin 2026/5861. Evacuate guests, drain the host and reboot; batch it with the other bulletin 5861 vGPU fixes.
References
Related entries
- NVIDIA GPU firmware: improper input validation reachable from a privileged local userCVE-2026-47546 · NVIDIA GPU firmware (input validation)Medium
- NVIDIA GPU Display Driver (Windows nvlddmkm.sys + Linux nvidia.ko): Improper access control in the kernel-mode layerCVE-2021-1076 · NVIDIA GPU Display Driver (Windows nvlddmkm.sys + Linux nvidia.ko)Medium
- NVIDIA GPU Display Driver (Windows nvlddmkm.sys + Linux nvidia.ko): Reference-count mishandling on a driver resourceCVE-2021-1077 · NVIDIA GPU Display Driver (Windows nvlddmkm.sys + Linux nvidia.ko)Medium
- GPU Display Driver: Local privesc (kernel buffer overflow)CVE-2023-0198 · GPU Display DriverMedium
- DGX H100 BMC (REST): Privesc via auth flawCVE-2023-31015 · DGX H100 BMC (REST)Medium
- DGX A100 SBIOS: Integer overflow in SBIOSCVE-2023-31034 · DGX A100 SBIOSMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.