CVE-2022-21816
07.02.2022, 20:15
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where a user in the guest OS can cause a GPU interrupt storm on the hypervisor host, leading to a denial of service.Enginsight
Vendor | Product | Version |
---|---|---|
nvidia | cloud_gaming_virtual_gpu | 𝑥 < 2022 |
nvidia | virtual_gpu | 8.0 ≤ 𝑥 < 8.10 |
nvidia | virtual_gpu | 11.0 ≤ 𝑥 < 11.7 |
nvidia | virtual_gpu | 13.0 ≤ 𝑥 < 13.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-284 - Improper Access ControlThe software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
- CWE-306 - Missing Authentication for Critical FunctionThe product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.