AVID-2026-R1164
Description
Vulnerability CVE-2022-42261
Details
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where an input index is not validated, which may lead to buffer overrun, which in turn may cause data tampering, information disclosure, or denial of service.
Reason for inclusion in AVID: CVE-2022-42261 describes a vulnerability in NVIDIA vGPU’s Virtual GPU Manager that can cause buffer overrun, leading to data tampering, information disclosure, or denial of service. NVIDIA vGPU software is a key component in AI deployment environments (virtualized GPU infrastructure used for ML training/inference). This is a software supply chain issue affecting components used to build/run general-purpose AI systems (drivers/virtualization in AI stacks). The report provides explicit vulnerability details and affected artifacts, enabling assessment and remediation.
References
- NVD entry
- https://nvidia.custhelp.com/app/answers/detail/a_id/5415
- https://security.gentoo.org/glsa/202310-02
Affected or Relevant Artifacts
- Developer: NVIDIA
- Deployer: NVIDIA
- Artifact Details:
| Type | Name |
|---|---|
| System | vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (Virtual GPU Manager) |
Impact
AVID Taxonomy Categorization
- Risk domains: Security
- SEP subcategories: S0100: Software Vulnerability
- Lifecycle stages: L06: Deployment
CVSS
| Version | 3.1 |
| Vector String | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| Base Score | 7.8 |
| Base Severity | 🔴 High |
| Attack Vector | LOCAL |
| Attack Complexity | 🟢 Low |
| Privileges Required | 🟢 Low |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | 🔴 High |
| Integrity Impact | 🔴 High |
| Availability Impact | 🔴 High |
CWE
| ID | Description |
|---|---|
| CWE-120 | CWE-120 |
Other information
- Report Type: Advisory
- Credits:
- Date Reported: 2022-12-30
- Version: 0.3.3
- AVID Entry