Skip to content
NvidiaCVE-2026-47496

Nvidia Virtual GPU Manager: out-of-bounds write

High7.3CVE-2026-47496 · Published Sep 30, 2026 · updated Oct 1, 2026

NVIDIA GPU Display Driver for Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin) where a guest VM user may cause an out-of-bounds write by sending a specially crafted RPC call to the host. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, and denial of service.

Nvidia advisory

Affected versions

PackageAffectedFixed in
Virtual GPU Manager
Product
<= 595.71.03(All versions prior to and including vGPU 20.1)No fix yet
<= 580.159.01(All versions prior to and including vGPU 19.5)No fix yet
<= 596.38(All versions prior to and including vGPU 20.1)No fix yet
<= 582.51(All versions prior to and including vGPU 19.5)No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-787

More Nvidia advisories

All Nvidia
Advisory
Nvidia GeForce: missing authorization
Medium5.5Sep 30
Nvidia GeForce: use after free
High7.0Sep 30
Nvidia GeForce: code execution
High7.8Sep 30
Nvidia GeForce: code execution
High7.8Sep 30
Nvidia GeForce: code execution
High7.8Sep 30
Nvidia GeForce: denial of service
High7.1Sep 30

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.