CVE-2026-47503: High severity Nvidia GPU Display Driver for Linux vulnerability
NVIDIA GPU Display Driver for Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a guest VM user may cause an out-of-bounds write by sending a crafted RPC message with invalid performance state list size parameters. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
Affected Software
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Systems using the NVIDIA GPU Display Driver for Linux with the Virtual GPU Manager (vGPU plugin) are in scope. The described attacker is a user within a guest virtual machine.
What access is required to exploit the vulnerability?
An attacker needs local, low-privileged access as a guest VM user and must be able to send a crafted RPC message to the vGPU plugin. No user interaction is required.
What could successful exploitation allow?
Successful exploitation may enable code execution or privilege escalation and could also result in data tampering, denial of service, or information disclosure.