Skip to content
NvidiaCVE-2026-47498

Nvidia Virtual GPU Manager: out-of-bounds write

High7.8CVE-2026-47498 · Published Sep 30, 2026 · updated Oct 1, 2026

NVIDIA vGPU Manager contains a vulnerability in the GPU System Processor (GSP) plugin where a guest VM user may cause an out-of-bounds write by sending a specially crafted RPC message. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.

Nvidia advisory

Affected versions

PackageAffectedFixed in
Virtual GPU Manager
Product
<= 595.71.03(All versions prior to and including vGPU 20.1)No fix yet
<= 580.159.01(All versions prior to and including vGPU 19.5)No fix yet
<= 596.38(All versions prior to and including vGPU 20.1)No fix yet
<= 582.51(All versions prior to and including vGPU 19.5)No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-787

More Nvidia advisories

All Nvidia
Advisory
Nvidia GeForce: missing authorization
Medium5.5Sep 30
Nvidia GeForce: use after free
High7.0Sep 30
Nvidia GeForce: code execution
High7.8Sep 30
Nvidia GeForce: code execution
High7.8Sep 30
Nvidia GeForce: code execution
High7.8Sep 30
Nvidia GeForce: denial of service
High7.1Sep 30

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.