First published: Fri Aug 05 2022(Updated: )
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it allows the guest VM to allocate resources for which the guest is not authorized. This vulnerability may lead to loss of data integrity and confidentiality, denial of service, or information disclosure.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nvidia Virtual GPU Graphics Driver | >=11.0<11.8 | |
Nvidia Virtual GPU Graphics Driver | >=13.0<13.3 | |
Nvidia Virtual GPU Graphics Driver | =14.0 | |
Nvidia Virtual GPU Graphics Driver | =14.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-31609 has been assigned a high severity rating due to its potential impact on data integrity and confidentiality.
To fix CVE-2022-31609, you should update to the latest version of NVIDIA vGPU software that addresses this vulnerability.
The impacts of CVE-2022-31609 can include loss of data integrity, confidentiality breaches, denial of service, or information disclosure.
CVE-2022-31609 affects NVIDIA vGPU Software versions 11.0 to 11.8, 13.0 to 13.3, and specifically versions 14.0 and 14.1.
Yes, CVE-2022-31609 can potentially be exploited by unauthorized guest VMs to allocate resources improperly.