NVIDIA vGPU Manager (vGPU plugin): The vGPU Manager grants a guest access to memory the guest does not own. That is the
Impact
The vGPU Manager grants a guest access to memory the guest does not own. That is the core vGPU isolation promise failing - a tenant VM reads memory belonging to the host or to another tenant's vGPU.
Who can reach it
Any unprivileged user inside a guest VM with a vGPU on the affected host.
What to do
Upgrade the vGPU Manager on the hypervisor host to the fixed vGPU release. The host component is a kernel module inside the hypervisor, so this is a full node drain: evacuate or power off every tenant VM on the host, upgrade, reboot the host. Guest drivers must be kept within the supported version skew and updated per VM (guest reboot). No VBIOS flash, but expect a maintenance window per host and a matching hypervisor-vendor package (VMware/Citrix/KVM/Nutanix builds ship separately).
References
Related entries
- NVIDIA vGPU Manager (vGPU plugin): Guest-supplied data size is not validated, letting a tenant tamper with host-sideCVE-2020-5970 · NVIDIA vGPU Manager (vGPU plugin)High
- NVIDIA vGPU Manager (vGPU plugin): Uninitialised local pointers later freed in the vGPU plugin - a guest-triggered freeCVE-2020-5972 · NVIDIA vGPU Manager (vGPU plugin)High
- NVIDIA vGPU Manager (vGPU plugin): Guest-supplied length not validated, allowing host-side data tampering or aCVE-2020-5985 · NVIDIA vGPU Manager (vGPU plugin)High
- NVIDIA vGPU Manager (vGPU plugin): Double free in the vGPU plugin, guest-triggered. Host heap corruption or disclosure.CVE-2020-5988 · NVIDIA vGPU Manager (vGPU plugin)High
- NVIDIA vGPU Manager (vGPU plugin): Unvalidated guest-supplied length in the vGPU pluginCVE-2021-1062 · NVIDIA vGPU Manager (vGPU plugin)High
- NVIDIA vGPU Manager (vGPU plugin): The plugin takes a value from the guest, casts it to a pointer and dereferences it.CVE-2021-1064 · NVIDIA vGPU Manager (vGPU plugin)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.