PT-2024-3873 · Nvidia+1 · Nvidia Gpu Display Driver+2
Published
2024-02-28
·
Updated
2024-08-07
·
CVE-2024-0077
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
NVIDIA Virtual GPU Manager (affected versions not specified)
NVIDIA GPU Display Driver (affected versions not specified)
Description:
The issue is related to a vulnerability in the vGPU plugin of the NVIDIA Virtual GPU Manager, which allows a guest OS to allocate resources for which it is not authorized. This can lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. Additionally, there is a vulnerability associated with a null pointer dereference in the NVIDIA GPU Display Driver, which can cause a denial of service, escalate privileges, and disclose protected information.
Recommendations:
For NVIDIA Virtual GPU Manager, consider restricting the allocation of resources to authorized guest OS instances until a patch is available.
For NVIDIA GPU Display Driver, as a temporary workaround, consider disabling the functionality related to the null pointer dereference until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nvidia Gpu Display Driver
Nvidia Virtual Gpu Manager
Red Os