CVE-2021-1060

NVIDIA vGPU software contains a vulnerability in the guest kernel mode driver and vGPU plugin, in which an input index is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:nvidia:virtual_gpu_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:virtual_gpu_manager:*:*:*:*:*:*:*:*
OR cpe:2.3:o:citrix:hypervisor:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:nutanix:ahv:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_kernel-based_virtual_machine:-:*:*:*:*:*:*:*
cpe:2.3:o:vmware:vsphere:-:*:*:*:*:*:*:*

History

14 Jan 2021, 18:22

Type Values Removed Values Added
References (CONFIRM) https://nvidia.custhelp.com/app/answers/detail/a_id/5142 - (CONFIRM) https://nvidia.custhelp.com/app/answers/detail/a_id/5142 - Vendor Advisory
CWE CWE-20
CPE cpe:2.3:o:nutanix:ahv:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_kernel-based_virtual_machine:-:*:*:*:*:*:*:*
cpe:2.3:o:vmware:vsphere:-:*:*:*:*:*:*:*
cpe:2.3:o:citrix:hypervisor:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:virtual_gpu_manager:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 3.6
v3 : 7.1

08 Jan 2021, 15:47

Type Values Removed Values Added
New CVE

Information

Published : 2021-01-08 15:15

Updated : 2023-12-10 13:41


NVD link : CVE-2021-1060

Mitre link : CVE-2021-1060

CVE.ORG link : CVE-2021-1060


JSON object : View

Products Affected

nvidia

  • virtual_gpu_manager

microsoft

  • windows

redhat

  • enterprise_linux_kernel-based_virtual_machine

linux

  • linux_kernel

vmware

  • vsphere

nutanix

  • ahv

citrix

  • hypervisor
CWE
CWE-20

Improper Input Validation