GPU VulnDB

Database/Firmware, BMC & network fabric

Dell OMSA: local heap overflow lets a low-privileged user escalate on the GPU host

CVSS 7.8CVE-2026-81474Firmware, BMC & network fabriccurated

Impact

A user with a local shell on a node running OMSA can overflow a heap buffer in the privileged agent and gain full control of the host. On a GPU node this matters wherever workloads get local host access - bare-metal tenancy, HPC login and compute nodes with interactive shells, or any container escape that lands a shell on the host - because OMSA elevates it straight to node compromise including hardware management. This is the local variant; CVE-2026-81477 is a separate remote heap overflow requiring high privilege.

Who can reach it

Local shell on a managed node with any low-privileged account.

What to do

Upgrade OMSA to 11.1.0.3 or later and restart the OMSA services. Nodes that do not need the OMSA agent locally can have it removed instead.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.