CVE-2024-0099

EUVD-2024-15900
NVIDIA vGPU software for Linux contains a vulnerability in the Virtual GPU Manager, where the guest OS could cause buffer overrun in the host. A successful exploit of this vulnerability might lead to information disclosure, data tampering, escalation of privileges, and denial of service.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 22%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
nvidiageforce
𝑥
< 555.52.04
ADP
nvidiageforce
𝑥
< 550.90.07
ADP
nvidiageforce
𝑥
< 535.183.01
ADP
nvidiageforce
𝑥
< 470.256.02
ADP
nvidiatesla
𝑥
< 550.90.07
ADP
nvidiatesla
𝑥
< 535.183.01
ADP
nvidiatesla
𝑥
< 470.256.02
ADP
nvidiaquadro
𝑥
< 555.52.04
ADP
nvidiaquadro
𝑥
< 550.90.07
ADP
nvidiaquadro
𝑥
< 535.183.01
ADP
nvidiaquadro
𝑥
< 470.256.02
ADP
nvidiartx
𝑥
< 555.52.04
ADP
nvidiartx
𝑥
< 550.90.07
ADP
nvidiartx
𝑥
< 535.183.01
ADP
nvidiartx
𝑥
< 470.256.02
ADP
nvidianvs
𝑥
< 555.52.04
ADP
nvidianvs
𝑥
< 550.90.07
ADP
nvidianvs
𝑥
< 535.183.01
ADP
nvidianvs
𝑥
< 470.256.02
ADP