Impact
NVIDIA vGPU Virtual GPU Manager for Linux contains an out‑of‑bounds read within its kernel mode layer (CWE‑125). A successful exploitation of this flaw can lead to code execution, denial of service, privilege escalation, information disclosure, and data tampering.
Affected Systems
The vulnerability affects NVIDIA Virtual GPU Manager for Linux deployed on supported systems. No specific versions have been listed in the available data, so all current installations of the Virtual GPU Manager are potentially impacted until a fix is applied.
Risk and Exploitability
The CVSS score of 7.8 classifies this as a high‑severity issue. Because EPSS data is unavailable, the exact likelihood of exploitation cannot be quantified, but the absence of a KEV listing suggests it has not yet been widely observed. The violation resides in kernel code, implying that an attacker would need local or privileged access to the host. If exploited, the attacker could execute arbitrary code, compromise system integrity, and disrupt service availability.
OpenCVE Enrichment