Executive brief
NVIDIA vGPU software, which allows multiple virtual machines to share a single physical graphics processor, contains a security flaw in its management component. A local attacker with limited access could exploit this vulnerability to crash the system, view sensitive information, or modify data. This could lead to service disruptions or unauthorized access to data within environments using virtualized graphics resources.
Technical details
An out-of-bounds access vulnerability (specifically CWE-787, Out-of-bounds Write) exists in the NVIDIA virtual GPU manager. The flaw is triggered when the manager improperly handles memory boundaries during processing. An attacker with local access and low privileges can exploit this, though the attack complexity is high, potentially leading to a denial of service (system crash), unauthorized information disclosure, or data tampering. Users are advised to refer to NVIDIA security advisory 5821 for specific version patches and mitigation steps.
Affected products
- NVIDIA vGPU software
Timeline
- 2026-05-26: disclosed: Initial publication of CVE-2026-24201