First published: Thu Jun 13 2024(Updated: )
NVIDIA vGPU software for Linux contains a vulnerability where the software can dereference a NULL pointer. A successful exploit of this vulnerability might lead to denial of service and undefined behavior in the vGPU plugin.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
NVIDIA vGPU Software | <13.11 | |
NVIDIA vGPU Software | >=14.0<16.6 | |
NVIDIA vGPU Software | >=17.0<17.2 | |
Any of | ||
Ubuntu | ||
Citrix Hypervisor | ||
Red Hat Enterprise Linux Kernel-based Virtual Machine | ||
VMware vSphere | ||
All of | ||
NVIDIA Cloud Gaming | <555.52.04 | |
Any of | ||
Red Hat Enterprise Linux Kernel-based Virtual Machine | ||
VMware vSphere |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-0086 is classified as a high severity vulnerability that can lead to denial of service.
To fix CVE-2024-0086, update your NVIDIA vGPU software to versions 13.11, 14.0 or later, 17.0 or later.
CVE-2024-0086 affects NVIDIA vGPU software versions up to 13.11, between 14.0 and 16.6, and between 17.0 and 17.2.
Exploiting CVE-2024-0086 may lead to denial of service and undefined behavior in the vGPU plugin.
CVE-2024-0086 affects NVIDIA vGPU software but does not directly affect operating systems like Ubuntu Linux, Citrix Hypervisor, Red Hat Enterprise Linux or VMware vSphere.