First published: Fri Jan 08 2021(Updated: )
NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which it obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer, which may lead to information disclosure or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA Virtual GPU Manager | >=8.0<8.6 | |
NVIDIA Virtual GPU Manager | >=11.0<11.3 | |
Citrix Hypervisor | ||
Nutanix Ahv | ||
Redhat Enterprise Linux Kernel-based Virtual Machine | ||
VMware vSphere |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-1064 is a vulnerability in the NVIDIA vGPU manager that allows an attacker to obtain sensitive information or cause a denial of service.
The severity of CVE-2021-1064 is high, with a CVSS score of 7.1.
NVIDIA vGPU manager versions 8.x prior to 8.6 and versions 11.0 to 11.3 are affected by CVE-2021-1064.
An attacker can exploit CVE-2021-1064 by providing malicious input to the vGPU plugin, causing it to obtain and dereference an invalid pointer.
No, Citrix Hypervisor and Nutanix Ahv are not vulnerable to CVE-2021-1064.