CVE-2021-1057

Severity
7.8HIGH
EPSS
0.1%
top 83.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 8
Latest updateJun 19

Description

NVIDIA Virtual GPU Manager NVIDIA vGPU manager contains a vulnerability in the vGPU plugin in which it allows guests to allocate some resources for which the guest is not authorized, which may lead to integrity and confidentiality loss, denial of service, or information disclosure. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

NVDnvidia/virtual_gpu_manager8.08.6+1
CVEListV5nvidia/nvidia_virtual_gpu_managerVersion 8.x (prior to 8.6) and version 11.0 (prior to 11.3)

🔴Vulnerability Details

2
GHSA
GHSA-mr62-x8vh-x4g5: NVIDIA Virtual GPU Manager NVIDIA vGPU manager contains a vulnerability in the vGPU plugin in which it allows guests to allocate some resources for wh2022-05-24
CVEList
CVE-2021-1057: NVIDIA Virtual GPU Manager NVIDIA vGPU manager contains a vulnerability in the vGPU plugin in which it allows guests to allocate some resources for wh2021-01-08

📋Vendor Advisories

1
Red Hat
kernel: btrfs: fix memory leak in __add_inode_ref()2024-06-19
CVE-2021-1057 (HIGH CVSS 7.8) | NVIDIA Virtual GPU Manager NVIDIA v | cvebase.io