CVE-2021-1063: High severity nvidia vgpu software vulnerability
NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which an input offset is not validated, which may lead to a buffer overread, which in turn may cause tampering of data, information disclosure, or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this NVIDIA vGPU manager vulnerability?
The vulnerability ID for this NVIDIA vGPU manager vulnerability is CVE-2021-1063.
What is the severity of CVE-2021-1063?
The severity of CVE-2021-1063 is high with a CVSS score of 7.8.
Which versions of vGPU are affected by this vulnerability?
This vulnerability affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).
What is the impact of this vulnerability?
This vulnerability may lead to a buffer overread, which can cause tampering of data, information disclosure, or denial of service.
How can I fix this vulnerability?
To fix this vulnerability, update NVIDIA vGPU manager to version 8.6 or version 11.3 or later.