CVE-2022-21816

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
07/02/2022
Last modified:
03/07/2023

Description

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where a user in the guest OS can cause a GPU interrupt storm on the hypervisor host, leading to a denial of service.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nvidia:cloud_gaming_virtual_gpu:*:*:*:*:*:*:*:* 2022 (excluding)
cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:* 8.0 (including) 8.10 (excluding)
cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:* 11.0 (including) 11.7 (excluding)
cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:* 13.0 (including) 13.2 (excluding)


References to Advisories, Solutions, and Tools