NVIDIA vGPU Manager (vGPU plugin): The vGPU plugin fails to bound an indexed or pointer-based access, and NVIDIA calls
Impact
The vGPU plugin fails to bound an indexed or pointer-based access, and NVIDIA calls out code execution, escalation and information disclosure. This is the guest-to-host escape shape - a tenant VM running code in the hypervisor's vGPU plugin owns every other tenant on that GPU. Affects vGPU 8.x before 8.4, 9.x before 9.4, 10.x before 10.3.
Who can reach it
Any unprivileged user inside a guest VM with a vGPU assigned.
What to do
Upgrade the vGPU Manager on the hypervisor host to the fixed vGPU release. The host component is a kernel module inside the hypervisor, so this is a full node drain: evacuate or power off every tenant VM on the host, upgrade, reboot the host. Guest drivers must be kept within the supported version skew and updated per VM (guest reboot). No VBIOS flash, but expect a maintenance window per host and a matching hypervisor-vendor package (VMware/Citrix/KVM/Nutanix builds ship separately).
References
Related entries
- NVIDIA vGPU Manager (vGPU plugin): Out-of-bounds read in the vGPU plugin that NVIDIA rates as code-execution capable. ACVE-2020-5971 · NVIDIA vGPU Manager (vGPU plugin)High
- NVIDIA vGPU Manager (vGPU plugin): Use-after-free while releasing resources in the vGPU plugin, rated code-executionCVE-2020-5984 · NVIDIA vGPU Manager (vGPU plugin)High
- NVIDIA vGPU Manager (vGPU plugin): Parameters stay writable by the guest after the plugin has validated them - aCVE-2020-5987 · NVIDIA vGPU Manager (vGPU plugin)High
- NVIDIA vGPU Manager (vGPU plugin): The vGPU plugin lets guests allocate resources they are not authorised to holdCVE-2021-1057 · NVIDIA vGPU Manager (vGPU plugin)High
- NVIDIA vGPU Manager (vGPU plugin): Unvalidated guest index leads to integer overflow in the host plugin, then tamperingCVE-2021-1059 · NVIDIA vGPU Manager (vGPU plugin)High
- NVIDIA vGPU Manager (vGPU plugin): Unvalidated offset produces a buffer overread in the host plugin. A tenant readsCVE-2021-1063 · NVIDIA vGPU Manager (vGPU plugin)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.