CVE-2022-42261
published 2022-12-30CVE-2022-42261: NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where an input index is not validated, which may lead to buffer…
PriorityP334high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.26%
17.3th percentile
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where an input index is not validated, which may lead to buffer overrun, which in turn may cause data tampering, information disclosure, or denial of service.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nvidia-graphics-drivers | < nvidia-graphics-drivers 510.108.03-1 (bookworm) | nvidia-graphics-drivers 510.108.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla | < nvidia-graphics-drivers 510.108.03-1 (bookworm) | nvidia-graphics-drivers 510.108.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-418 | < nvidia-graphics-drivers 510.108.03-1 (bookworm) | nvidia-graphics-drivers 510.108.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-450 | < nvidia-graphics-drivers 510.108.03-1 (bookworm) | nvidia-graphics-drivers 510.108.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-460 | < nvidia-graphics-drivers 510.108.03-1 (bookworm) | nvidia-graphics-drivers 510.108.03-1 (bookworm) |
| debian | nvidia-graphics-drivers-tesla-470 | < nvidia-graphics-drivers 510.108.03-1 (bookworm) | nvidia-graphics-drivers 510.108.03-1 (bookworm) |
| nvidia | cloud_gaming | < 525.60.12 | 525.60.12 |
| nvidia | gpu_display_driver | >= 450 < 450.216.04 | 450.216.04 |
| nvidia | gpu_display_driver | >= 470 < 470.161.03 | 470.161.03 |
| nvidia | gpu_display_driver | >= 510 < 510.108.03 | 510.108.03 |
| nvidia | virtual_gpu | < 11.11 | 11.11 |
| nvidia | virtual_gpu | >= 12.0 < 13.6 | 13.6 |
| nvidia | virtual_gpu | >= 14.0 < 14.4 | 14.4 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.8HIGH
vendor_debian7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2022-42261: nvidia-graphics-drivers - NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU p...
vendor_debian·2022·CVSS 7.8
CVE-2022-42261 [HIGH] CVE-2022-42261: nvidia-graphics-drivers - NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU p...
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where an input index is not validated, which may lead to buffer overrun, which in turn may cause data tampering, information disclosure, or denial of service.
Scope: local
bookworm: resolved (fixed in 510.108.03-1)
bullseye: resolved (fixed in 470.161.03-1)
forky: resolved (fixed in 510.108.03-1)
sid: resolved (fixed in 510.108.03-1)
trixie: resolved (fixed in 510.108.03-1)
OSV
CVE-2022-42261: NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where an input index is not validated, which may lead to buffe
osv·2022-12-30·CVSS 7.8
CVE-2022-42261 [HIGH] CVE-2022-42261: NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where an input index is not validated, which may lead to buffe
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where an input index is not validated, which may lead to buffer overrun, which in turn may cause data tampering, information disclosure, or denial of service.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-12-30
Published