CVE-2020-5971: High severity nvidia vgpu software vulnerability
NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which the software reads from a buffer by using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer, which may lead to code execution, denial of service, escalation of privileges, or information disclosure. This affects vGPU version 8.x (prior to 8.4), version 9.x (prior to 9.4) and version 10.x (prior to 10.3).
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this NVIDIA Virtual GPU Manager vulnerability?
The vulnerability ID for this NVIDIA Virtual GPU Manager vulnerability is CVE-2020-5971.
What is the severity level of CVE-2020-5971?
CVE-2020-5971 has a severity level of 7.8 (High).
Which software is affected by CVE-2020-5971?
NVIDIA Virtual GPU Manager versions 8.0 to 8.3, 9.0 to 9.3, and 10.0 to 10.2 are affected by CVE-2020-5971.
What is the impact of CVE-2020-5971?
CVE-2020-5971 may lead to code execution, denial of service, and escalation of privileges.
How can I fix the CVE-2020-5971 vulnerability?
To fix the CVE-2020-5971 vulnerability, update NVIDIA Virtual GPU Manager to a version outside the affected range.