CVE-2022-28191: Medium severity nvidia virtual gpu graphics driver vulnerability
Published May 17, 2022
·Updated
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where uncontrolled resource consumption can be triggered by an unprivileged regular user, which may lead to denial of service.
Affected Software
3 affected components
Nvidia Virtual GPU>=11.0<11.8
Nvidia Virtual GPU>=13.0<13.3
Nvidia Virtual GPU=14.0
Remediation
Patch Available
Event History
May 17, 2022
CVE Published
via MITRE·07:15 PM
Data Sourced
via MITRE·07:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-28191?
CVE-2022-28191 has a medium severity level due to its potential for denial of service.
2
How do I fix CVE-2022-28191?
To fix CVE-2022-28191, update to a patched version of NVIDIA vGPU software that addresses the vulnerability.
3
What are the affected versions of NVIDIA vGPU software for CVE-2022-28191?
CVE-2022-28191 affects NVIDIA vGPU software versions from 11.0 to 11.8, 13.0 to 13.3, and the exact version 14.0.
4
Who can trigger the vulnerability CVE-2022-28191?
CVE-2022-28191 can be triggered by an unprivileged regular user, leading to uncontrolled resource consumption.
5
What impact does CVE-2022-28191 have on systems?
The impact of CVE-2022-28191 is a potential denial of service, which may disrupt the availability of GPU resources.