CVE-2021-1087

NVIDIA vGPU driver contains a vulnerability in the Virtual GPU Manager (vGPU plugin), which could allow an attacker to retrieve information that could lead to a Address Space Layout Randomization (ASLR) bypass. This affects vGPU version 12.x (prior to 12.2), version 11.x (prior to 11.4) and version 8.x (prior to 8.7).
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:nvidia:virtual_gpu_manager:*:*:*:*:*:*:*:*
OR cpe:2.3:o:citrix:hypervisor:-:*:*:*:*:*:*:*
cpe:2.3:o:nutanix:ahv:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_kernel-based_virtual_machine:-:*:*:*:*:*:*:*
cpe:2.3:o:vmware:vsphere:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:a:nvidia:virtual_gpu_manager:*:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:virtual_gpu_manager:*:*:*:*:*:*:*:*
OR cpe:2.3:o:citrix:hypervisor:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_kernel-based_virtual_machine:-:*:*:*:*:*:*:*
cpe:2.3:o:vmware:vsphere:-:*:*:*:*:*:*:*

History

07 May 2021, 20:37

Type Values Removed Values Added
References (CONFIRM) https://nvidia.custhelp.com/app/answers/detail/a_id/5172 - (CONFIRM) https://nvidia.custhelp.com/app/answers/detail/a_id/5172 - Vendor Advisory
CWE CWE-200
CPE cpe:2.3:o:vmware:vsphere:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_kernel-based_virtual_machine:-:*:*:*:*:*:*:*
cpe:2.3:o:citrix:hypervisor:-:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:virtual_gpu_manager:*:*:*:*:*:*:*:*
cpe:2.3:o:nutanix:ahv:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 2.1
v3 : 5.5

29 Apr 2021, 19:35

Type Values Removed Values Added
New CVE

Information

Published : 2021-04-29 19:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-1087

Mitre link : CVE-2021-1087

CVE.ORG link : CVE-2021-1087


JSON object : View

Products Affected

redhat

  • enterprise_linux_kernel-based_virtual_machine

nutanix

  • ahv

nvidia

  • virtual_gpu_manager

citrix

  • hypervisor

vmware

  • vsphere