GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA vGPU Manager on Linux: incorrect resource transfer across isolation boundaries

CVSS 7.8CVE-2026-47574NVIDIA / GPU stackcurated

Impact

A resource is transferred between isolation spheres incorrectly, meaning an object ends up on the wrong side of the guest and host boundary the vGPU Manager maintains. This is an isolation defect rather than a memory-safety accident, so it can be triggered through supported operations instead of by corrupting anything. For an operator selling vGPU slices it means a resource belonging to one sphere becoming reachable from another, with code execution and data tampering listed as the consequences.

Who can reach it

Local to the vGPU host, reachable through the vGPU Manager's resource handling; in this bulletin's vGPU set the attacker is a user in a guest VM with a vGPU assigned.

What to do

Upgrade the Virtual GPU Manager on all Linux hypervisor hosts per NVIDIA bulletin 2026/5861; no fixed version is given in this record. Evacuate each host and reboot it to install the update.

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.