CVE-2022-28192: Use After Free
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where it may lead to a use-after-free, which in turn may cause denial of service. This attack is complex to carry out because the attacker needs to have control over freeing some host side resources out of sequence, which requires elevated privileges.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-28192?
CVE-2022-28192 is a moderate severity vulnerability that can lead to denial of service.
How do I fix CVE-2022-28192?
To mitigate CVE-2022-28192, upgrade to the latest version of NVIDIA vGPU software that addresses this vulnerability.
What are the affected versions for CVE-2022-28192?
CVE-2022-28192 affects NVIDIA vGPU software versions between 11.0 to 11.8, 13.0 to 13.3, and specifically version 14.0.
What kind of attack does CVE-2022-28192 involve?
CVE-2022-28192 involves a complex use-after-free vulnerability that requires control over host-side resource management.
Can CVE-2022-28192 be exploited remotely?
Exploitation of CVE-2022-28192 requires local access to the affected NVIDIA vGPU software environment.