CVE Vulnerabilities

CVE-2022-31614

Double Free

Published: Aug 05, 2022 | Modified: Aug 10, 2022
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin) where it may double-free some resources. An attacker may exploit this vulnerability with other vulnerabilities to cause denial of service, code execution, and information disclosure.

Weakness

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Affected Software

Name Vendor Start Version End Version
Virtual_gpu Nvidia 11.0 (including) 11.8 (excluding)
Virtual_gpu Nvidia 13.0 (including) 13.3 (excluding)
Virtual_gpu Nvidia 14.0 (including) 14.0 (including)
Virtual_gpu Nvidia 14.1 (including) 14.1 (including)

Potential Mitigations

References