NVIDIA GPU Display Driver Vulnerability in Virtual GPU Manager
CVE-2026-47496

7.3HIGH

Key Information:

Vendor

Nvidia

Vendor
CVE Published:
30 September 2026

What is CVE-2026-47496?

The NVIDIA GPU Display Driver for Linux has a vulnerability in the Virtual GPU Manager that allows a guest VM user to execute an out-of-bounds write by sending a specially crafted RPC call to the host system. This security flaw can be exploited to escalate privileges, manipulate data, and potentially lead to denial of service, impacting the overall integrity and reliability of the affected systems.

Affected Version(s)

Virtual GPU Manager Azure Local, Windows Server(vGPU 19) 582.51(All versions prior to and including vGPU 19.5)

Virtual GPU Manager Azure Local, Windows Server(vGPU 20) 596.38(All versions prior to and including vGPU 20.1)

Virtual GPU Manager XenServer, VMware vSphere, Red Hat Enterprise Linux KVM, Ubuntu(vGPU 19) 580.159.01(All versions prior to and including vGPU 19.5)

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.