NVIDIA GPU Display Driver Vulnerability in Virtual GPU Manager
CVE-2026-47496
What is CVE-2026-47496?
The NVIDIA GPU Display Driver for Linux has a vulnerability in the Virtual GPU Manager that allows a guest VM user to execute an out-of-bounds write by sending a specially crafted RPC call to the host system. This security flaw can be exploited to escalate privileges, manipulate data, and potentially lead to denial of service, impacting the overall integrity and reliability of the affected systems.
Affected Version(s)
Virtual GPU Manager Azure Local, Windows Server(vGPU 19) 582.51(All versions prior to and including vGPU 19.5)
Virtual GPU Manager Azure Local, Windows Server(vGPU 20) 596.38(All versions prior to and including vGPU 20.1)
Virtual GPU Manager XenServer, VMware vSphere, Red Hat Enterprise Linux KVM, Ubuntu(vGPU 19) 580.159.01(All versions prior to and including vGPU 19.5)