CVE-2021-1060: Input Validation
Published Jan 8, 2021
·Updated
NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and vGPU plugin, in which an input index is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).
Affected Software
8 affected components
Nvidia Virtual GPU Manager>=8.0<8.6
Nvidia Virtual GPU Manager>=11.0<11.3
Citrix Hypervisor
Linux Linux kernel
Microsoft Windows
Nutanix Ahv
redhat Enterprise Linux Kernel-based Virtual Machine
VMware vSphere
Event History
Jan 8, 2021
CVE Published
via MITRE·03:05 PM
Data Sourced
via MITRE·03:05 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-1060.
2
What is the severity of CVE-2021-1060?
The severity of CVE-2021-1060 is high with a CVSS score of 7.1.
3
Which software is affected by CVE-2021-1060?
NVIDIA vGPU software versions 8.x (prior to 8.6) and 11.0 (prior to 11.3) are affected.
4
How can the vulnerability be exploited?
The vulnerability can be exploited by tampering with data or causing denial of service through the guest kernel mode driver and vGPU plugin.
5
How can I fix CVE-2021-1060?
To fix CVE-2021-1060, update your NVIDIA vGPU software to version 8.6 or 11.3 or later.