CVE-2026-47496: High severity Nvidia GPU Display Driver for Linux vulnerability
NVIDIA GPU Display Driver for Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin) where a guest VM user may cause an out-of-bounds write by sending a specially crafted RPC call to the host. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, and denial of service.
Affected Software
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
The affected component is the Virtual GPU Manager (vGPU plugin) in the NVIDIA GPU Display Driver for Linux. Exposure is relevant where guest VM users can communicate with the host through the vGPU RPC interface.
What access does an attacker need to exploit it?
An attacker must be a user in a guest VM and be able to send a specially crafted RPC call to the host. The CVSS vector indicates local access and low privileges are required, with no user interaction.
What could a successful exploit allow?
A successful exploit may enable privilege escalation, data tampering, and denial of service. The reported flaw is an out-of-bounds write in the vGPU plugin.