Executive brief
NVIDIA vGPU software, which allows multiple virtual machines to share a single physical graphics processor, contains a security flaw in its management component. A local attacker with limited access could exploit this vulnerability to crash the system, steal sensitive data, or gain higher-level administrative privileges. This could lead to a total compromise of the host system and the virtual environments it supports.
Technical details
A use-after-free (UAF) vulnerability exists in the NVIDIA virtual GPU manager component of the vGPU software. The flaw involves improper management of stack memory, which can be triggered by a local attacker with low privileges. While the attack complexity is rated as high, a successful exploit allows for a range of impacts including denial of service, information disclosure, data tampering, and arbitrary code execution. The vulnerability is tracked as CWE-416 and affects the management layer that interfaces between the guest VMs and the physical hardware.
Affected products
- NVIDIA vGPU software
Timeline
- 2026-05-26: disclosed: Initial publication of the CVE record.
- 2026-05-26: advisory: NVIDIA security advisory published.