Description
NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause a use-after-free for stack memory. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, data tampering, and code execution.
References (3)
Core 3
Scores
CVSS v3
7.0
EPSS
0.0017
EPSS Percentile
6.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-416
Status
published
Products (5)
NVIDIA/Virtual GPU Manager
535.288.01(All versions prior to and including vGPU 16.13)
NVIDIA/Virtual GPU Manager
580.126.08(All versions prior to and including vGPU 19.4)
NVIDIA/Virtual GPU Manager
582.16(All versions prior to and including vGPU 19.4)
NVIDIA/Virtual GPU Manager
595.58.02(All versions up to and including the March 2026 release)
NVIDIA/Virtual GPU Manager
595.94(All versions prior to and including vGPU 20.0)
Published
May 26, 2026
Tracked Since
May 26, 2026