NVIDIA vGPU software (guest kernel-mode driver + vGPU plugin): Unvalidated length across the guest kernel-mode driver
Impact
Unvalidated length across the guest kernel-mode driver and vGPU plugin boundary. Tenant-to-host disclosure or tampering. vGPU 12.x before 12.2, 11.x before 11.4, 8.x before 8.7.
Who can reach it
Any user inside a guest VM with a vGPU.
What to do
Upgrade the vGPU Manager on the host and the vGPU guest driver inside each tenant VM to the fixed release. Host side is a node drain plus reboot; guest side is a per-VM driver install and reboot. Because the guest driver is inside tenant-controlled VMs, in a multi-tenant estate you cannot fully remediate the guest half yourself - the host-side upgrade is the control you own. No VBIOS flash.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.