Description
NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Published: 2026-09-30
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

NVIDIA vGPU Virtual GPU Manager for Linux contains an out‑of‑bounds read within its kernel mode layer (CWE‑125). A successful exploitation of this flaw can lead to code execution, denial of service, privilege escalation, information disclosure, and data tampering.

Affected Systems

The vulnerability affects NVIDIA Virtual GPU Manager for Linux deployed on supported systems. No specific versions have been listed in the available data, so all current installations of the Virtual GPU Manager are potentially impacted until a fix is applied.

Risk and Exploitability

The CVSS score of 7.8 classifies this as a high‑severity issue. Because EPSS data is unavailable, the exact likelihood of exploitation cannot be quantified, but the absence of a KEV listing suggests it has not yet been widely observed. The violation resides in kernel code, implying that an attacker would need local or privileged access to the host. If exploited, the attacker could execute arbitrary code, compromise system integrity, and disrupt service availability.

Generated by OpenCVE AI on September 30, 2026 at 17:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Download and install the latest NVIDIA Virtual GPU Manager update from the NVIDIA product‑security repository.
  • Reboot the system to load the patched kernel module.
  • Consider disabling the Virtual GPU Manager until the update is applied, or monitor system logs for anomalous kernel activity.

Generated by OpenCVE AI on September 30, 2026 at 17:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in NVIDIA Virtual GPU Manager Kernel Layer

Wed, 30 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description NVIDIA vGPU Virtual GPU Manager for Linux contains a vulnerability in the kernel mode layer where an attacker could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-09-30T17:29:26.452Z

Reserved: 2026-05-19T19:55:43.812Z

Link: CVE-2026-47536

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-30T16:17:20.677

Modified: 2026-09-30T16:30:23.773

Link: CVE-2026-47536

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T17:30:19Z

Weaknesses