Use-after-free Vulnerability in NVIDIA vGPU Software
CVE-2026-24200
What is CVE-2026-24200?
The capabilities of NVIDIA vGPU software may be compromised due to a flaw in the virtual GPU manager, which could allow an attacker to exploit a use-after-free condition affecting stack memory. If leveraged, this vulnerability poses significant risks, including denial of service, potential privilege escalation, unauthorized information access, data alteration, and execution of arbitrary code. Organizations using NVIDIA vGPU should take immediate action to mitigate these security dangers.
Affected Version(s)
Virtual GPU Manager Azure Local 595.94(All versions prior to and including vGPU 20.0)
Virtual GPU Manager Azure Local 582.16(All versions prior to and including vGPU 19.4)
Virtual GPU Manager Red Hat Enterprise Linux KVM 595.58.02(All versions up to and including the March 2026 release)