Description
NVIDIA vGPU Virtual GPU Manager for Windows and Linux contains a vulnerability in the kernel mode layer, where a guest user could cause an integer overflow leading to memory corruption. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Published: 2026-09-30
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Privilege escalation and code execution via kernel‑mode memory corruption
Action: Patch Immediately
AI Analysis

Impact

NVIDIA’s vGPU Virtual GPU Manager for Windows and Linux contains a kernel‑mode integer overflow that can corrupt memory when a guest VM performs certain operations. This vulnerability can allow a local attacker to execute arbitrary code, crash the host, or extract sensitive information from the system. The impact is substantial, potentially leading to full system takeover, data tampering and denial of service. The weakness is catalogued as CWE‑190, an integer overflow flaw.

Affected Systems

All NVIDIA products that rely on the vGPU Virtual GPU Manager, including GeForce, RTX, Quadro, NVS and Tesla GPUs, on both Windows and Linux platforms. Specific affected firmware or driver versions are not disclosed in the current data, so all deployments of the vGPU Manager should be considered at risk unless verified otherwise.

Risk and Exploitability

The CVSS score of 7.8 rates the issue as high severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog, but kernel‑level integer overflows are historically exploitable with moderate effort. The attack vector involves a guest user executing code that triggers the overflow, leading to host kernel memory corruption. Successful exploitation would grant the attacker escalation of privileges and code execution on the host.

Generated by OpenCVE AI on September 30, 2026 at 19:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the NVIDIA vGPU Virtual GPU Manager and related driver stack to the latest release that incorporates the vendor‑published fix.
  • Restrict guest user privileges so that processes lacking elevated rights cannot invoke the vulnerable kernel routines.
  • Implement monitoring for kernel panics, memory corruption events, and anomalous guest activity, and remediate promptly if indicators are detected.

Generated by OpenCVE AI on September 30, 2026 at 19:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Title Kernel Integer Overflow in NVIDIA vGPU Virtual GPU Manager May Permit Code Execution and Privilege Escalation

Wed, 30 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 30 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description NVIDIA vGPU Virtual GPU Manager for Windows and Linux contains a vulnerability in the kernel mode layer, where a guest user could cause an integer overflow leading to memory corruption. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Weaknesses CWE-190
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-09-30T17:59:53.906Z

Reserved: 2026-05-19T19:55:41.286Z

Link: CVE-2026-47502

cve-icon Vulnrichment

Updated: 2026-09-30T17:57:51.805Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T16:17:15.110

Modified: 2026-09-30T18:18:20.557

Link: CVE-2026-47502

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T19:15:07Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound