CVE-2021-1119: Double Free
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can double-free a pointer, which may lead to denial of service. This flaw may result in a write-what-where condition, allowing an attacker to execute arbitrary code impacting integrity and availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-1119?
CVE-2021-1119 has a high severity rating as it can lead to denial of service and arbitrary code execution.
How do I fix CVE-2021-1119?
To fix CVE-2021-1119, update your NVIDIA vGPU software to a version that is not affected, specifically versions 8.10 or later, 11.7 or later, 12.5 or later, or 13.2 or later.
What impact does CVE-2021-1119 have on system security?
CVE-2021-1119 can compromise system integrity and availability, potentially allowing unauthorized code execution.
Which versions of NVIDIA vGPU are affected by CVE-2021-1119?
CVE-2021-1119 affects NVIDIA vGPU software versions 8.0 to 8.9, 11.0 to 11.6, 12.0 to 12.4, and 13.0 to 13.1.
Can CVE-2021-1119 be exploited remotely?
Yes, CVE-2021-1119 can potentially be exploited remotely, allowing attackers to execute arbitrary code.