NVIDIA vGPU Manager (vGPU plugin): Stack buffer overflow in the vGPU Manager with enough control for a guest to place a
Impact
Stack buffer overflow in the vGPU Manager with enough control for a guest to place a ROP chain on the host stack. This is the most explicitly weaponisable of the 2021 vGPU set - guest-to-host code execution on the hypervisor. vGPU 12.x before 12.3, 11.x before 11.5, 8.x before 8.8.
Who can reach it
Any unprivileged user inside a guest VM with a vGPU on the affected host.
What to do
Upgrade the vGPU Manager on the hypervisor host to the fixed vGPU release. The host component is a kernel module inside the hypervisor, so this is a full node drain: evacuate or power off every tenant VM on the host, upgrade, reboot the host. Guest drivers must be kept within the supported version skew and updated per VM (guest reboot). No VBIOS flash, but expect a maintenance window per host and a matching hypervisor-vendor package (VMware/Citrix/KVM/Nutanix builds ship separately).
References
Related entries
- NVIDIA vGPU Manager (vGPU plugin): A guest-supplied string may not be null-terminated, and the host plugin reads pastCVE-2021-1120 · NVIDIA vGPU Manager (vGPU plugin)High
- NVIDIA vGPU Manager (vGPU plugin): Time-of-check to time-of-use on a shared resource between guest and host plugin. ACVE-2020-5969 · NVIDIA vGPU Manager (vGPU plugin)Medium
- NVIDIA vGPU Manager (vGPU plugin): The plugin keeps using a resource it validated after the guest has changed it - aCVE-2021-1061 · NVIDIA vGPU Manager (vGPU plugin)Medium
- NVIDIA vGPU Manager (vGPU plugin): A guest VM hands the vGPU Manager a wrongly sized buffer and drives the host into anCVE-2019-5696 · NVIDIA vGPU Manager (vGPU plugin)Medium
- NVIDIA vGPU Manager (vGPU plugin): Unvalidated guest-supplied index in the vGPU plugin. A tenant VM crashes the hostCVE-2020-5959 · NVIDIA vGPU Manager (vGPU plugin)Medium
- NVIDIA vGPU Manager (vGPU plugin): Guest-supplied size not validated in the vGPU pluginCVE-2020-5986 · NVIDIA vGPU Manager (vGPU plugin)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.