CVE-2026-47498: High severity Nvidia vGPU Manager vulnerability
NVIDIA vGPU Manager contains a vulnerability in the GPU System Processor (GSP) plugin where a guest VM user may cause an out-of-bounds write by sending a specially crafted RPC message. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
A user in a guest VM is the stated attacker. Exploitation requires the ability to send a specially crafted RPC message to the GSP plugin in NVIDIA vGPU Manager.
What impact could successful exploitation have?
Successful exploitation may enable code execution, privilege escalation, data tampering, denial of service, and information disclosure. The listed CVSS vector indicates local attack access and low privileges are required, with no user interaction required.
How can I determine whether my environment is affected?
Identify systems running NVIDIA vGPU Manager and determine whether guest VM users can interact with the GSP plugin through RPC messaging. The supplied information does not identify affected versions or configurations.