CVE-2021-1064
Severity CVSS v4.0:
Pending analysis
Type:
CWE-476
NULL Pointer Dereference
Publication date:
08/01/2021
Last modified:
11/01/2021
Description
NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which it obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer, which may lead to information disclosure or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).
Impact
Base Score 3.x
7.10
Severity 3.x
HIGH
Base Score 2.0
3.60
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:nvidia:virtual_gpu_manager:*:*:*:*:*:*:*:* | 8.0 (including) | 8.6 (excluding) |
| cpe:2.3:a:nvidia:virtual_gpu_manager:*:*:*:*:*:*:*:* | 11.0 (including) | 11.3 (excluding) |
| cpe:2.3:o:citrix:hypervisor:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:nutanix:ahv:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:redhat:enterprise_linux_kernel-based_virtual_machine:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:vmware:vsphere:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



