CVE-2024-0084

NVIDIA vGPU software for Linux contains a vulnerability in the Virtual GPU Manager, where the guest OS could execute privileged operations. A successful exploit of this vulnerability might lead to information disclosure, data tampering, escalation of privileges, and denial of service.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*
OR cpe:2.3:o:canonical:ubuntu_linux:-:*:*:*:*:*:*:*
cpe:2.3:o:citrix:hypervisor:-:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_kernel-based_virtual_machine:-:*:*:*:*:*:*:*
cpe:2.3:o:vmware:vsphere:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:nvidia:cloud_gaming:*:*:*:*:*:*:*:*
OR cpe:2.3:o:redhat:enterprise_linux_kernel-based_virtual_machine:-:*:*:*:*:*:*:*
cpe:2.3:o:vmware:vsphere:-:*:*:*:*:*:*:*

History

15 Aug 2024, 22:00

Type Values Removed Values Added
References () https://nvidia.custhelp.com/app/answers/detail/a_id/5551 - () https://nvidia.custhelp.com/app/answers/detail/a_id/5551 - Vendor Advisory
CPE cpe:2.3:a:nvidia:cloud_gaming:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_kernel-based_virtual_machine:-:*:*:*:*:*:*:*
cpe:2.3:o:citrix:hypervisor:-:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:virtual_gpu:*:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:-:*:*:*:*:*:*:*
cpe:2.3:o:vmware:vsphere:-:*:*:*:*:*:*:*
First Time Redhat enterprise Linux Kernel-based Virtual Machine
Citrix
Redhat
Canonical ubuntu Linux
Vmware
Canonical
Citrix hypervisor
Nvidia cloud Gaming
Nvidia virtual Gpu
Nvidia
Vmware vsphere
CWE NVD-CWE-Other

17 Jun 2024, 12:43

Type Values Removed Values Added
Summary
  • (es) El software NVIDIA vGPU para Linux contiene una vulnerabilidad en Virtual GPU Manager, donde el sistema operativo invitado podría ejecutar operaciones privilegiadas. Una explotación exitosa de esta vulnerabilidad podría conducir a la divulgación de información, la manipulación de datos, la escalada de privilegios y la denegación de servicio.

13 Jun 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-13 22:15

Updated : 2024-08-15 22:00


NVD link : CVE-2024-0084

Mitre link : CVE-2024-0084

CVE.ORG link : CVE-2024-0084


JSON object : View

Products Affected

redhat

  • enterprise_linux_kernel-based_virtual_machine

canonical

  • ubuntu_linux

nvidia

  • virtual_gpu
  • cloud_gaming

vmware

  • vsphere

citrix

  • hypervisor
CWE
NVD-CWE-Other CWE-250

Execution with Unnecessary Privileges