CVE-2026-47497

Summary

NVIDIA Virtual GPU Manager contains a vulnerability in the GPU System Processor (GSP) tracing component where a guest VM user may cause improper access by sending crafted data through a shared buffer. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.

Affected Software

VendorProductVersion RangeStatus
NVIDIAVirtual GPU Manager595.71.03(All versions prior to and including vGPU 20.1)affected
NVIDIAVirtual GPU Manager580.159.01(All versions prior to and including vGPU 19.5)affected
NVIDIAVirtual GPU Manager596.38(All versions prior to and including vGPU 20.1)affected
NVIDIAVirtual GPU Manager582.51(All versions prior to and including vGPU 19.5)affected

Weaknesses

  • CWE-367: CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References