GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA vGPU Manager (vGPU plugin): MULTI-TENANT ISOLATION: the guest can write to a shared memory location

CVE-2021-1085NVIDIA / GPU stackcurated

Impact

MULTI-TENANT ISOLATION: the guest can write to a shared memory location after the host has validated its contents - a double-fetch that NVIDIA rates as escalation-capable. The tenant passes the host's checks with clean data, then substitutes their own. vGPU 12.x before 12.2, 11.x before 11.4, 8.x before 8.7.

Who can reach it

Any unprivileged user inside a guest VM able to race the host's validation window.

What to do

Upgrade the vGPU Manager on the hypervisor host to the fixed vGPU release. The host component is a kernel module inside the hypervisor, so this is a full node drain: evacuate or power off every tenant VM on the host, upgrade, reboot the host. Guest drivers must be kept within the supported version skew and updated per VM (guest reboot). No VBIOS flash, but expect a maintenance window per host and a matching hypervisor-vendor package (VMware/Citrix/KVM/Nutanix builds ship separately).

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.