CVE-2021-1064: Null Pointer Dereference
NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which it obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer, which may lead to information disclosure or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-1064?
CVE-2021-1064 is a vulnerability in the NVIDIA vGPU manager that allows an attacker to obtain sensitive information or cause a denial of service.
What is the severity of CVE-2021-1064?
The severity of CVE-2021-1064 is high, with a CVSS score of 7.1.
Which versions of NVIDIA vGPU manager are affected by CVE-2021-1064?
NVIDIA vGPU manager versions 8.x prior to 8.6 and versions 11.0 to 11.3 are affected by CVE-2021-1064.
How can CVE-2021-1064 be exploited?
An attacker can exploit CVE-2021-1064 by providing malicious input to the vGPU plugin, causing it to obtain and dereference an invalid pointer.
Is Citrix Hypervisor or Nutanix Ahv vulnerable to CVE-2021-1064?
No, Citrix Hypervisor and Nutanix Ahv are not vulnerable to CVE-2021-1064.