First published: Thu Nov 02 2023(Updated: )
NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a malicious user in the guest VM can cause a NULL-pointer dereference, which may lead to denial of service.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA Virtual GPU | <13.9 | |
NVIDIA Virtual GPU | >=14.0<15.4 | |
NVIDIA Virtual GPU | >=16.0<16.2 | |
Microsoft Azure Stack Hci | ||
Canonical Ubuntu Linux | ||
Citrix Hypervisor | ||
Linux-kvm Kernel Virtual Machine | ||
Redhat Enterprise Linux | ||
VMware vSphere |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-31021.
The vulnerability in the NVIDIA vGPU software allows a malicious user in the guest VM to cause a NULL-pointer dereference, leading to a denial of service.
The affected software is NVIDIA Virtual GPU.
The severity rating of CVE-2023-31021 vulnerability is medium with a CVSS score of 5.5.
To fix this vulnerability, update the NVIDIA vGPU software to version 16.3 or later.