CVE-2022-42262
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where an input index is not validated, which may lead to buffer overrun, which in turn may cause data tampering, information disclosure, or denial of service.
Affected (7)
Products: Nvidia: Virtual Gpu, Cloud Gaming, Gpu Display Driver
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 11.11 |
| Running on/with | Platform Versions |
|---|---|
Linux Linux Kernel | All versions |
Vmware Vsphere | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 525.60.12 |
| Running on/with | Platform Versions |
|---|---|
Citrix Hypervisor | All versions |
Redhat Enterprise Linux Kernel Based Virtual Machine | All versions |
Configuration C
| Running on/with | Platform Versions |
|---|---|
Nvidia Geforce | All versions |
Nvidia Nvs | All versions |
Nvidia Quadro | All versions |
Nvidia Rtx | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| From 450 to 450.216.04 |
| Running on/with | Platform Versions |
|---|---|
Nvidia Tesla | All versions |
Related CWEs
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.
CWE-787
Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.