Description
NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the firmware where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Published: 2026-09-30
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Potential code execution, privilege escalation, data disclosure, denial of service
Action: Assess Impact
AI Analysis

Impact

The vulnerability resides in the firmware of NVIDIA's Virtual GPU Manager for Linux. The flaw is an out‑of‑bounds read that, if successfully exploited, could allow an attacker to read adjacent memory. An attacker might leverage this read to obtain sensitive data or gain foothold for further attack. In the most severe scenario, the exploitation could lead to arbitrary code execution, escalation of privileges, and data tampering. The weakness aligns with CWE‑125.

Affected Systems

The affected product is NVIDIA Virtual GPU Manager for Linux. All current releases are impacted; specific version data is not supplied by the CNA. The vulnerability affects Linux hosts that run the vGPU Manager.

Risk and Exploitability

The CVSS base score is 7.8, reflecting substantial impact. The EPSS score is not available, so the current probability of exploitation cannot be quantified. The vulnerability is not listed in CISA's KEV catalog, indicating no known active exploitation. Attackers require local or remote access to the vGPU firmware; the exact attack vector is not detailed in the description, thus it is inferred that local privilege escalation or VM escape may be required.

Generated by OpenCVE AI on September 30, 2026 at 17:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Obtain and apply the latest NVIDIA Virtual GPU Manager firmware patch once released.
  • If a patch is not immediately available, isolate affected virtual GPUs by restricting network access and monitoring for anomalous reads.
  • Review and enforce kernel hardening options such as SELinux or AppArmor policies around vGPU processes to reduce the impact of a potential memory read.
  • Contact NVIDIA support for guidance on interim mitigations and confirm that the environment is not exposed to untrusted guests.

Generated by OpenCVE AI on September 30, 2026 at 17:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title Unbounded Read in NVIDIA vGPU Firmware

Wed, 30 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the firmware where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-09-30T17:29:26.589Z

Reserved: 2026-05-19T19:55:43.812Z

Link: CVE-2026-47535

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T16:17:20.523

Modified: 2026-09-30T16:30:23.773

Link: CVE-2026-47535

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T17:30:19Z

Weaknesses