CVE-2023-31021: CVE
Published Nov 2, 2023
·Updated
NVIDIA vGPU software for Windows and Linux contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a malicious user in the guest VM can cause a NULL-pointer dereference, which may lead to denial of service.
Affected Software
9 affected components
Nvidia Virtual GPU<13.9
Nvidia Virtual GPU>=14.0<15.4
Nvidia Virtual GPU>=16.0<16.2
Microsoft Azure Stack HCI
Canonical Ubuntu Linux
Citrix Hypervisor
Linux-kvm Kernel Virtual Machine
redhat Enterprise Linux
VMware vSphere
Event History
Nov 2, 2023
CVE Published
06:56 PM
Data Sourced
06:56 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this NVIDIA vGPU software vulnerability?
The vulnerability ID is CVE-2023-31021.
2
What is the description of the vulnerability?
The vulnerability in the NVIDIA vGPU software allows a malicious user in the guest VM to cause a NULL-pointer dereference, leading to a denial of service.
3
What is the affected software?
The affected software is NVIDIA Virtual GPU.
4
What is the severity rating of CVE-2023-31021 vulnerability?
The severity rating of CVE-2023-31021 vulnerability is medium with a CVSS score of 5.5.
5
How can I fix this vulnerability?
To fix this vulnerability, update the NVIDIA vGPU software to version 16.3 or later.