Junglewise Threat Intelligence

CVE-2026-24201: NVIDIA vGPU out-of-bounds access in virtual GPU manager

CVE-2026-24201 · Severity: medium · CVSS 5.8 · Published 2026-05-26

Vendors: Nvidia.

Executive brief

NVIDIA vGPU software, which allows multiple virtual machines to share a single physical graphics processor, contains a security flaw in its management component. A local attacker with limited access could exploit this vulnerability to crash the system, view sensitive information, or modify data. This could lead to service disruptions or unauthorized access to data within environments using virtualized graphics resources.

Technical details

An out-of-bounds access vulnerability (specifically CWE-787, Out-of-bounds Write) exists in the NVIDIA virtual GPU manager. The flaw is triggered when the manager improperly handles memory boundaries during processing. An attacker with local access and low privileges can exploit this, though the attack complexity is high, potentially leading to a denial of service (system crash), unauthorized information disclosure, or data tampering. Users are advised to refer to NVIDIA security advisory 5821 for specific version patches and mitigation steps.

Affected products

  • NVIDIA vGPU software

Timeline

  • 2026-05-26: disclosed: Initial publication of CVE-2026-24201

References

Related threats