NVIDIA vGPU Manager (vGPU plugin): Guest-supplied length not validated, allowing host-side data tampering or a
Impact
Guest-supplied length not validated, allowing host-side data tampering or a shared-GPU outage. vGPU 8.x before 8.5, 10.x before 10.4, and 11.0.
Who can reach it
Any unprivileged user inside a guest VM with a vGPU.
What to do
Upgrade the vGPU Manager on the hypervisor host to the fixed vGPU release. The host component is a kernel module inside the hypervisor, so this is a full node drain: evacuate or power off every tenant VM on the host, upgrade, reboot the host. Guest drivers must be kept within the supported version skew and updated per VM (guest reboot). No VBIOS flash, but expect a maintenance window per host and a matching hypervisor-vendor package (VMware/Citrix/KVM/Nutanix builds ship separately).
References
Related entries
- NVIDIA vGPU Manager (vGPU plugin): Double free in the vGPU plugin, guest-triggered. Host heap corruption or disclosure.CVE-2020-5988 · NVIDIA vGPU Manager (vGPU plugin)High
- NVIDIA vGPU Manager (vGPU plugin): Unvalidated guest-supplied length in the vGPU pluginCVE-2021-1062 · NVIDIA vGPU Manager (vGPU plugin)High
- NVIDIA vGPU Manager (vGPU plugin): The plugin takes a value from the guest, casts it to a pointer and dereferences it.CVE-2021-1064 · NVIDIA vGPU Manager (vGPU plugin)High
- NVIDIA vGPU Manager (vGPU plugin): Unvalidated guest input in the vGPU plugin leading to host data tampering or aCVE-2021-1065 · NVIDIA vGPU Manager (vGPU plugin)High
- NVIDIA vGPU Manager (vGPU plugin): The vGPU Manager lets guests control resources they are not entitled to, whichCVE-2021-1086 · NVIDIA vGPU Manager (vGPU plugin)High
- NVIDIA vGPU Manager (vGPU plugin): Double free in the vGPU Manager that NVIDIA explicitly describes as aCVE-2021-1119 · NVIDIA vGPU Manager (vGPU plugin)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.