CVE-2023-0197

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
01/04/2023
Last modified:
10/04/2023

Description

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious user in a guest VM can cause a NULL-pointer dereference, which may lead to denial of service.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:* 11.12 (excluding)
cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:* 13.0 (including) 13.7 (excluding)
cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:* 15.0 (including) 15.2 (excluding)
cpe:2.3:o:citrix:hypervisor:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_kernel-based_virtual_machine:-:*:*:*:*:*:*:*
cpe:2.3:o:vmware:vsphere:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools