First published: Fri Jan 08 2021(Updated: )
NVIDIA Virtual GPU Manager NVIDIA vGPU manager contains a vulnerability in the vGPU plugin in which it allows guests to allocate some resources for which the guest is not authorized, which may lead to integrity and confidentiality loss, denial of service, or information disclosure. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA vGPU software | >=8.0<8.6 | |
NVIDIA vGPU software | >=11.0<11.3 | |
Citrix Hypervisor | ||
Nutanix Ahv | ||
Redhat Enterprise Linux Kernel-based Virtual Machine | ||
VMware vSphere |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-1057 is a vulnerability in the NVIDIA Virtual GPU Manager that allows guests to allocate unauthorized resources, potentially leading to integrity and confidentiality loss, denial of service, or information disclosure.
The NVIDIA Virtual GPU Manager versions between 8.0 and 8.6, as well as versions between 11.0 and 11.3, are affected by CVE-2021-1057.
CVE-2021-1057 has a severity rating of 7.8 (High).
CVE-2021-1057 can be exploited by guests who allocate unauthorized resources, potentially leading to various security risks.
Yes, NVIDIA has released a fix for CVE-2021-1057. It is recommended to update to a non-vulnerable version of the NVIDIA Virtual GPU Manager.