CVE-2026-47497: High severity Nvidia Virtual GPU Manager vulnerability
NVIDIA Virtual GPU Manager contains a vulnerability in the GPU System Processor (GSP) tracing component where a guest VM user may cause improper access by sending crafted data through a shared buffer. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
Affected Software
Event History
Frequently Asked Questions
Who is in a position to exploit this issue?
A user in a guest virtual machine can trigger the issue. The attack is local (AV:L), requires low privileges (PR:L), and does not require user interaction (UI:N).
What security impact could successful exploitation have?
Successful exploitation may allow code execution, privilege escalation, data tampering, denial of service, and information disclosure. The CVSS vector rates confidentiality, integrity, and availability impact as high.
What component should be prioritized for remediation or exposure review?
Review NVIDIA Virtual GPU Manager deployments that use the GPU System Processor (GSP) tracing component and shared buffers accessible from guest VMs. The described attack path involves crafted data sent through such a shared buffer.