CVE-2021-1084

NVIDIA vGPU driver contains a vulnerability in the guest kernel mode driver and Virtual GPU Manager (vGPU plugin), in which an input length is not validated, which may lead to information disclosure, tampering of data or denial of service. This affects vGPU version 12.x (prior to 12.2) and version 11.x (prior to 11.4).
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:nvidia:virtual_gpu_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:virtual_gpu_manager:*:*:*:*:*:*:*:*
OR cpe:2.3:o:citrix:hypervisor:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_kernel-based_virtual_machine:-:*:*:*:*:*:*:*
cpe:2.3:o:vmware:vsphere:-:*:*:*:*:*:*:*

History

28 May 2021, 13:43

Type Values Removed Values Added
CVSS v2 : 3.6
v3 : 7.1
v2 : 4.6
v3 : 7.8

21 May 2021, 18:15

Type Values Removed Values Added
Summary NVIDIA vGPU driver contains a vulnerability in the guest kernel mode driver and Virtual GPU Manager (vGPU plugin), in which an input length is not validated, which may lead to tampering of data or denial of service. This affects vGPU version 12.x (prior to 12.2) and version 11.x (prior to 11.4). NVIDIA vGPU driver contains a vulnerability in the guest kernel mode driver and Virtual GPU Manager (vGPU plugin), in which an input length is not validated, which may lead to information disclosure, tampering of data or denial of service. This affects vGPU version 12.x (prior to 12.2) and version 11.x (prior to 11.4).

07 May 2021, 20:45

Type Values Removed Values Added
References (CONFIRM) https://nvidia.custhelp.com/app/answers/detail/a_id/5172 - (CONFIRM) https://nvidia.custhelp.com/app/answers/detail/a_id/5172 - Vendor Advisory
CWE CWE-20
CVSS v2 : unknown
v3 : unknown
v2 : 3.6
v3 : 7.1
CPE cpe:2.3:o:vmware:vsphere:-:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:virtual_gpu_manager:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_kernel-based_virtual_machine:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:citrix:hypervisor:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

29 Apr 2021, 19:35

Type Values Removed Values Added
New CVE

Information

Published : 2021-04-29 19:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-1084

Mitre link : CVE-2021-1084

CVE.ORG link : CVE-2021-1084


JSON object : View

Products Affected

redhat

  • enterprise_linux_kernel-based_virtual_machine

linux

  • linux_kernel

microsoft

  • windows

nvidia

  • virtual_gpu_manager

citrix

  • hypervisor

vmware

  • vsphere
CWE
CWE-20

Improper Input Validation