CVE-2021-1119
Severity CVSS v4.0:
Pending analysis
Type:
CWE-415
Double Free
Publication date:
29/10/2021
Last modified:
02/11/2021
Description
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where it can double-free a pointer, which may lead to denial of service. This flaw may result in a write-what-where condition, allowing an attacker to execute arbitrary code impacting integrity and availability.
Impact
Base Score 3.x
7.10
Severity 3.x
HIGH
Base Score 2.0
3.60
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:* | 8.0 (including) | 8.9 (excluding) |
| cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:* | 11.0 (including) | 11.6 (excluding) |
| cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:* | 12.0 (including) | 12.4 (excluding) |
| cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:* | 13.0 (including) | 13.1 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



