CVE-2021-1120: High severity nvidia virtual gpu graphics driver vulnerability
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a string provided by the guest OS may not be properly null terminated. The guest OS or attacker has no ability to push content to the plugin through this vulnerability, which may lead to information disclosure, data tampering, unauthorized code execution, and denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-1120?
CVE-2021-1120 has been classified as a medium-severity vulnerability.
How do I fix CVE-2021-1120?
To mitigate CVE-2021-1120, update the NVIDIA vGPU software to the latest patched version.
Which versions of NVIDIA vGPU software are affected by CVE-2021-1120?
CVE-2021-1120 affects specific versions of NVIDIA vGPU software between 8.0 and 8.9, 11.0 and 11.6, 12.0 and 12.4, as well as 13.0 and 13.1.
Can an attacker exploit CVE-2021-1120 remotely?
No, CVE-2021-1120 does not provide an attacker the ability to push content through the vulnerability.
What type of attack does CVE-2021-1120 relate to?
CVE-2021-1120 relates to an information disclosure vulnerability due to improper string handling in the Virtual GPU Manager.