NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which local pointer variables are not initialized and may be freed later, which may lead to tampering or denial of service. This affects vGPU version 8.x (prior to 8.4), version 9.x (prior to 9.4) and version 10.x (prior to 10.3).
The product attempts to return a memory resource to the system, but it calls the wrong release function or calls the appropriate release function incorrectly.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Virtual_gpu_manager | Nvidia | 8.0 (including) | 8.3 (including) |
Virtual_gpu_manager | Nvidia | 9.0 (including) | 9.3 (including) |
Virtual_gpu_manager | Nvidia | 10.0 (including) | 10.2 (including) |
This weakness can take several forms, such as: