Multiple vulnerabilities in NVIDIA Virtual GPU Manager



Published: 2024-02-29
Risk Medium
Patch available YES
Number of vulnerabilities 7
CVE-ID CVE-2022-42265
CVE-2024-0073
CVE-2024-0074
CVE-2024-0078
CVE-2024-0075
CVE-2024-0077
CVE-2024-0079
CWE-ID CWE-190
CWE-250
CWE-788
CWE-476
CWE-285
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
NVIDIA vGPU software (Virtual GPU Manager) Driver
Hardware solutions / Drivers

Vendor nVidia

Security Bulletin

This security bulletin contains information about 7 vulnerabilities.

1) Integer overflow

EUVDB-ID: #VU86927

Risk: Low

CVSSv3.1: 5.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2022-42265

CWE-ID: CWE-190 - Integer overflow

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to integer overflow within the NVIDIA GPU Display Driver in the kernel mode layer (nvidia.ko). A local user can trigger an integer overflow and perform a denial of service (DoS) attack or gain access to sensitive information.

Mitigation

Install update from vendor's website.

Vulnerable software versions

NVIDIA vGPU software (Virtual GPU Manager) Driver: before 16.4

External links

http://nvidia.custhelp.com/app/answers/detail/a_id/5520


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Execution with unnecessary privileges

EUVDB-ID: #VU86923

Risk: Low

CVSSv3.1: 7.7 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-0073

CWE-ID: CWE-250 - Execution with Unnecessary Privileges

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to execution with unnecessary privileges in the kernel mode layer within the NVIDIA GPU Display Driver for Windows. A local low-privileged user can execute arbitrary code with elevated privileges.

Mitigation

Install update from vendor's website.

Vulnerable software versions

NVIDIA vGPU software (Virtual GPU Manager) Driver: before 16.4

External links

http://nvidia.custhelp.com/app/answers/detail/a_id/5520


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Access of Memory Location After End of Buffer

EUVDB-ID: #VU86924

Risk: Low

CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-0074

CWE-ID: CWE-788 - Access of Memory Location After End of Buffer

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in the NVIDIA GPU Display Driver for Linux. A local user can access a memory location after the end of the buffer and perform a denial of service (DoS) attack.

Mitigation

Install update from vendor's website.

Vulnerable software versions

NVIDIA vGPU software (Virtual GPU Manager) Driver: before 16.4

External links

http://nvidia.custhelp.com/app/answers/detail/a_id/5520


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

4) NULL pointer dereference

EUVDB-ID: #VU86925

Risk: Low

CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-0078

CWE-ID: CWE-476 - NULL Pointer Dereference

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error. A local user can pass specially crafted data to the driver and perform a denial of service (DoS) attack.

Mitigation

Install update from vendor's website.

Vulnerable software versions

NVIDIA vGPU software (Virtual GPU Manager) Driver: before 16.4

External links

http://nvidia.custhelp.com/app/answers/detail/a_id/5520


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

5) NULL pointer dereference

EUVDB-ID: #VU86926

Risk: Low

CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-0075

CWE-ID: CWE-476 - NULL Pointer Dereference

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error. A local user can pass specially crafted data to the driver and perform a denial of service (DoS) attack.

Mitigation

Install update from vendor's website.

Vulnerable software versions

NVIDIA vGPU software (Virtual GPU Manager) Driver: before 16.4

External links

http://nvidia.custhelp.com/app/answers/detail/a_id/5520


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

6) Improper Authorization

EUVDB-ID: #VU86929

Risk: Medium

CVSSv3.1: 6.3 [CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-0077

CWE-ID: CWE-285 - Improper Authorization

Exploit availability: No

Description

The vulnerability allows a malicious guest to escalate privileges on the system.

The vulnerability exists due to improper authorization within the vGPU plugin when allocating resources for the guest OS. A malicious guest can escalate privileges on the system.

Mitigation

Install update from vendor's website.

Vulnerable software versions

NVIDIA vGPU software (Virtual GPU Manager) Driver: before 16.4

External links

http://nvidia.custhelp.com/app/answers/detail/a_id/5520


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

7) NULL pointer dereference

EUVDB-ID: #VU86930

Risk: Low

CVSSv3.1: 4.3 [CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-0079

CWE-ID: CWE-476 - NULL Pointer Dereference

Exploit availability: No

Description

The vulnerability allows a malicious guest to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error in the kernel mode layer. A malicious guest can pass specially crafted data to the driver and perform a denial of service (DoS) attack.

Mitigation

Install update from vendor's website.

Vulnerable software versions

NVIDIA vGPU software (Virtual GPU Manager) Driver: before 16.4

External links

http://nvidia.custhelp.com/app/answers/detail/a_id/5520


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###