NVIDIA vGPU Manager kernel module (nvidia.ko, host): NULL dereference in the host-side nvidia.ko under the vGPU
Impact
NULL dereference in the host-side nvidia.ko under the vGPU Manager. A guest can panic the hypervisor host's kernel module, killing every VM sharing that GPU.
Who can reach it
Any unprivileged user inside a guest VM with a vGPU.
What to do
Upgrade the vGPU Manager on the hypervisor host to the fixed vGPU release. The host component is a kernel module inside the hypervisor, so this is a full node drain: evacuate or power off every tenant VM on the host, upgrade, reboot the host. Guest drivers must be kept within the supported version skew and updated per VM (guest reboot). No VBIOS flash, but expect a maintenance window per host and a matching hypervisor-vendor package (VMware/Citrix/KVM/Nutanix builds ship separately).
References
Related entries
- NVIDIA vGPU Manager kernel module (nvidia.ko, host): One vGPU can starve the other vGPUs hosted on the same physicalCVE-2021-1121 · NVIDIA vGPU Manager kernel module (nvidia.ko, host)Medium
- NVIDIA vGPU Manager kernel module (nvidia.ko, host): The host vGPU kernel module dereferences an unvalidated user-spaceCVE-2021-1100 · NVIDIA vGPU Manager kernel module (nvidia.ko, host)Medium
- NVIDIA vGPU guest graphics driver: Bad cleanup on a failure path in the guest driver crashes the tenant's own VMCVE-2020-5961 · NVIDIA vGPU guest graphics driverMedium
- NVIDIA Windows GPU Display Driver, DirectX 11 user-mode driver (nvwgf2um.dll): A crafted shader causes an out-of-boundsCVE-2020-5965 · NVIDIA Windows GPU Display Driver, DirectX 11 user-mode driver (nvwgf2um.dll)Medium
- NVIDIA vGPU Manager (vGPU plugin): Guest-supplied size not validated in the vGPU pluginCVE-2020-5986 · NVIDIA vGPU Manager (vGPU plugin)Medium
- NVIDIA vGPU Manager (vGPU plugin): NULL dereference in the vGPU plugin reachable from a guest - one tenant crashes theCVE-2020-5989 · NVIDIA vGPU Manager (vGPU plugin)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.