Home » Database

AVID-2026-R1164

Description

Vulnerability CVE-2022-42261

Details

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where an input index is not validated, which may lead to buffer overrun, which in turn may cause data tampering, information disclosure, or denial of service.

Reason for inclusion in AVID: CVE-2022-42261 describes a vulnerability in NVIDIA vGPU’s Virtual GPU Manager that can cause buffer overrun, leading to data tampering, information disclosure, or denial of service. NVIDIA vGPU software is a key component in AI deployment environments (virtualized GPU infrastructure used for ML training/inference). This is a software supply chain issue affecting components used to build/run general-purpose AI systems (drivers/virtualization in AI stacks). The report provides explicit vulnerability details and affected artifacts, enabling assessment and remediation.

References

Affected or Relevant Artifacts

  • Developer: NVIDIA
  • Deployer: NVIDIA
  • Artifact Details:
TypeName
SystemvGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (Virtual GPU Manager)

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CVSS

Version3.1
Vector StringCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score7.8
Base Severity🔴 High
Attack VectorLOCAL
Attack Complexity🟢 Low
Privileges Required🟢 Low
User InteractionNONE
ScopeUNCHANGED
Confidentiality Impact🔴 High
Integrity Impact🔴 High
Availability Impact🔴 High

CWE

IDDescription
CWE-120CWE-120

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2022-12-30
  • Version: 0.3.3
  • AVID Entry