First published: Fri Jan 08 2021(Updated: )
NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which an input offset is not validated, which may lead to a buffer overread, which in turn may cause tampering of data, information disclosure, or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA Virtual GPU Manager | >=8.0<8.6 | |
NVIDIA Virtual GPU Manager | >=11.0<11.3 | |
Citrix Hypervisor | ||
Nutanix Ahv | ||
Redhat Enterprise Linux Kernel-based Virtual Machine | ||
VMware vSphere |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this NVIDIA vGPU manager vulnerability is CVE-2021-1063.
The severity of CVE-2021-1063 is high with a CVSS score of 7.8.
This vulnerability affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).
This vulnerability may lead to a buffer overread, which can cause tampering of data, information disclosure, or denial of service.
To fix this vulnerability, update NVIDIA vGPU manager to version 8.6 or version 11.3 or later.