CVE-2026-47497
Awaiting Analysis Awaiting Analysis - Queue

Improper Access in NVIDIA Virtual GPU Manager via GSP Tracing

Vulnerability report for CVE-2026-47497, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: NVIDIA Corporation

Description

NVIDIA Virtual GPU Manager contains a vulnerability in the GPU System Processor (GSP) tracing component where a guest VM user may cause improper access by sending crafted data through a shared buffer. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
nvidia virtual_gpu_manager *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-367 The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

NVIDIA Virtual GPU Manager has a flaw in its GPU System Processor tracing component. A guest VM user can exploit this by sending specially crafted data through a shared buffer. This improper access could allow them to execute code, escalate privileges, tamper with data, cause denial of service, or disclose information.

Detection Guidance

Detection of this vulnerability requires monitoring for unusual activity in the NVIDIA Virtual GPU Manager, particularly in the GPU System Processor (GSP) tracing component. Check for unexpected guest VM interactions with shared buffers or elevated privileges. Review logs for signs of tampering, code execution attempts, or denial of service events. Use NVIDIA's provided tools or security advisories for specific detection commands.

Impact Analysis

If exploited, this vulnerability could let an attacker gain control over the system, steal sensitive data, alter or delete files, crash the system, or access confidential information. It primarily affects systems using NVIDIA Virtual GPU Manager.

Mitigation Strategies

Apply the latest security patches or updates from NVIDIA for the Virtual GPU Manager. Restrict guest VM access to shared buffers and limit privileges where possible. Monitor network traffic for suspicious activity targeting the GSP component. Consider isolating vulnerable systems until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-47497. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart