CVE-2021-1100: Medium severity nvidia virtual gpu graphics driver vulnerability
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager kernel mode driver (nvidia.ko), in which a pointer to a user-space buffer is not validated before it is dereferenced, which may lead to denial of service. This affects vGPU version 12.x (prior to 12.3), version 11.x (prior to 11.5) and version 8.x (prior 8.8).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-1100?
CVE-2021-1100 has been assigned a medium severity rating due to the potential for denial of service.
How do I fix CVE-2021-1100?
To fix CVE-2021-1100, update the NVIDIA vGPU software to version 12.3 or later for 12.x versions, or to version 11.5 or later for 11.x versions.
Which NVIDIA vGPU software versions are affected by CVE-2021-1100?
CVE-2021-1100 affects NVIDIA vGPU software versions 11.x prior to 11.5 and 12.x prior to 12.3.
What is the impact of exploiting CVE-2021-1100?
Exploiting CVE-2021-1100 may lead to a denial of service by dereferencing an unvalidated pointer.
Is there a workaround for CVE-2021-1100 if I can't update immediately?
There are currently no publicly documented workarounds for CVE-2021-1100, so an update is recommended.