NVIDIA vGPU software (guest kernel-mode driver + vGPU plugin): Unvalidated index across the guest driver and vGPU
Impact
Unvalidated index across the guest driver and vGPU plugin boundary, giving a tenant host-side data tampering or a shared-GPU outage. vGPU 8.x before 8.6, 11.0 before 11.3.
Who can reach it
Any user inside a guest VM with a vGPU.
What to do
Upgrade the vGPU Manager on the host and the vGPU guest driver inside each tenant VM to the fixed release. Host side is a node drain plus reboot; guest side is a per-VM driver install and reboot. Because the guest driver is inside tenant-controlled VMs, in a multi-tenant estate you cannot fully remediate the guest half yourself - the host-side upgrade is the control you own. No VBIOS flash.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.