NVIDIA vGPU software - Virtual GPU Manager (host-side vGPU plugin / nvidia.ko): A privileged attacker escalates through
Impact
A privileged attacker escalates through NVIDIA GPU software with a changed CVSS scope, reaching code execution, data corruption and information disclosure beyond the component. The Virtual GPU Manager is in the affected list, so on a vGPU host the scope change means the hypervisor. The attacker sits inside a tenant guest VM and the blast radius is the hypervisor host, which is running every other tenant's vGPU on the same physical GPU. This is precisely the boundary a vGPU-based multi-tenant offering is sold on. NVIDIA's description is unusually vague here; treat the scope-changed 8.2 on a vGPU host as the worst case until you have your own detail.
Who can reach it
A tenant inside their own guest VM, driving the paravirtualised vGPU control interface. Several of these need only an unprivileged process in the guest; the rest need guest root, which a tenant already has on a VM they rented. No host credentials are involved at any point.
What to do
Patch the vGPU Manager on the hypervisor host per bulletin 5586. Cost: the highest of any class here. The host driver cannot be reloaded while vGPUs are attached, so every tenant VM on that hypervisor must be live-migrated or powered off - a full host drain. NVIDIA also enforces a supported host/guest driver skew, so budget a matching guest-driver campaign in the same window or tenants lose their vGPU on next boot.
References
Related entries
- NVIDIA vGPU software - Virtual GPU Manager (host-side vGPU plugin / nvidia.ko): The vGPU plugin lets a guest VMCVE-2022-31609 · NVIDIA vGPU software - Virtual GPU Manager (host-side vGPU plugin / nvidia.ko)High
- NVIDIA vGPU software - Virtual GPU Manager (host-side vGPU plugin / nvidia.ko): An unvalidated input index in the vGPUCVE-2022-42261 · NVIDIA vGPU software - Virtual GPU Manager (host-side vGPU plugin / nvidia.ko)High
- NVIDIA vGPU software - Virtual GPU Manager (host-side vGPU plugin / nvidia.ko): A tenant who has compromised their ownCVE-2024-0127 · NVIDIA vGPU software - Virtual GPU Manager (host-side vGPU plugin / nvidia.ko)High
- NVIDIA vGPU software - Virtual GPU Manager (host-side vGPU plugin / nvidia.ko): A malicious guest drives the VirtualCVE-2025-23352 · NVIDIA vGPU software - Virtual GPU Manager (host-side vGPU plugin / nvidia.ko)High
- NVIDIA vGPU software - Virtual GPU Manager (host-side vGPU plugin / nvidia.ko): A malicious guest causes the VirtualCVE-2025-33220 · NVIDIA vGPU software - Virtual GPU Manager (host-side vGPU plugin / nvidia.ko)High
- NVIDIA vGPU software - Virtual GPU Manager (host-side vGPU plugin / nvidia.ko): A second unvalidated index path in theCVE-2022-42262 · NVIDIA vGPU software - Virtual GPU Manager (host-side vGPU plugin / nvidia.ko)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.