NVIDIA vGPU Manager (vGPU plugin): The vGPU Manager lets guests control resources they are not entitled to, which
Impact
The vGPU Manager lets guests control resources they are not entitled to, which NVIDIA describes as integrity and confidentiality loss. A tenant reaching resources outside its partition is the vGPU security model failing. vGPU 12.x before 12.2, 11.x before 11.4, 8.x before 8.7.
Who can reach it
Any unprivileged user inside a guest VM with a vGPU.
What to do
Upgrade the vGPU Manager on the hypervisor host to the fixed vGPU release. The host component is a kernel module inside the hypervisor, so this is a full node drain: evacuate or power off every tenant VM on the host, upgrade, reboot the host. Guest drivers must be kept within the supported version skew and updated per VM (guest reboot). No VBIOS flash, but expect a maintenance window per host and a matching hypervisor-vendor package (VMware/Citrix/KVM/Nutanix builds ship separately).
References
Related entries
- NVIDIA vGPU Manager (vGPU plugin): Double free in the vGPU Manager that NVIDIA explicitly describes as aCVE-2021-1119 · NVIDIA vGPU Manager (vGPU plugin)High
- NVIDIA vGPU Manager (vGPU plugin): Stack buffer overflow in the vGPU Manager with enough control for a guest to place aCVE-2021-1099 · NVIDIA vGPU Manager (vGPU plugin)High
- NVIDIA vGPU Manager (vGPU plugin): A guest-supplied string may not be null-terminated, and the host plugin reads pastCVE-2021-1120 · NVIDIA vGPU Manager (vGPU plugin)High
- NVIDIA vGPU Manager (vGPU plugin): Time-of-check to time-of-use on a shared resource between guest and host plugin. ACVE-2020-5969 · NVIDIA vGPU Manager (vGPU plugin)Medium
- NVIDIA vGPU Manager (vGPU plugin): The plugin keeps using a resource it validated after the guest has changed it - aCVE-2021-1061 · NVIDIA vGPU Manager (vGPU plugin)Medium
- NVIDIA vGPU Manager (vGPU plugin): A guest VM hands the vGPU Manager a wrongly sized buffer and drives the host into anCVE-2019-5696 · NVIDIA vGPU Manager (vGPU plugin)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.