NVIDIA vGPU Manager (vGPU plugin): A guest VM hands the vGPU Manager a wrongly sized buffer and drives the host into an
Impact
A guest VM hands the vGPU Manager a wrongly sized buffer and drives the host into an out-of-bounds GPU access. One tenant VM can take down the vGPU host, which means every other tenant sharing that physical GPU goes with it.
Who can reach it
Any unprivileged user inside any guest VM assigned a vGPU on the host.
What to do
Upgrade the vGPU Manager on the hypervisor host to the fixed vGPU release. The host component is a kernel module inside the hypervisor, so this is a full node drain: evacuate or power off every tenant VM on the host, upgrade, reboot the host. Guest drivers must be kept within the supported version skew and updated per VM (guest reboot). No VBIOS flash, but expect a maintenance window per host and a matching hypervisor-vendor package (VMware/Citrix/KVM/Nutanix builds ship separately).
References
Related entries
- NVIDIA vGPU Manager (vGPU plugin): Unvalidated guest-supplied index in the vGPU plugin. A tenant VM crashes the hostCVE-2020-5959 · NVIDIA vGPU Manager (vGPU plugin)Medium
- NVIDIA vGPU Manager (vGPU plugin): Guest-supplied size not validated in the vGPU pluginCVE-2020-5986 · NVIDIA vGPU Manager (vGPU plugin)Medium
- NVIDIA vGPU Manager (vGPU plugin): NULL dereference in the vGPU plugin reachable from a guest - one tenant crashes theCVE-2020-5989 · NVIDIA vGPU Manager (vGPU plugin)Medium
- NVIDIA vGPU Manager (vGPU plugin): Unvalidated guest input causes unbounded resource consumption on the host, so oneCVE-2021-1066 · NVIDIA vGPU Manager (vGPU plugin)Medium
- NVIDIA vGPU Manager (vGPU plugin): Information retrievable by a guest that defeats ASLR on the host side. On its own itCVE-2021-1087 · NVIDIA vGPU Manager (vGPU plugin)Medium
- NVIDIA vGPU Manager (vGPU plugin): NULL dereference in the vGPU plugin, guest-reachableCVE-2021-1101 · NVIDIA vGPU Manager (vGPU plugin)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.