CVE-2022-42261
Description
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where an input index is not validated, which may lead to buffer overrun, which in turn may cause data tampering, information disclosure, or denial of service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
NVIDIA vGPU Virtual GPU Manager has an unvalidated input index that leads to buffer overrun, enabling data tampering, information disclosure, or denial of service.
Vulnerability
CVE-2022-42261 is a vulnerability in the NVIDIA vGPU software, specifically in the Virtual GPU Manager (vGPU plugin). The issue is that an input index is not validated, which can lead to a buffer overrun. This affects NVIDIA vGPU versions as distributed with NVIDIA Drivers. The vulnerability is present in the vGPU plugin that manages virtual GPU instances within the host kernel [1].
Exploitation
An attacker requires local access to the system where the NVIDIA vGPU plugin is loaded. The attacker must be able to interact with the vGPU manager, potentially through a virtual machine that has access to the vGPU. By supplying an invalid index, the attacker triggers a buffer overrun. The exact sequence of steps is not detailed but involves providing an out-of-range index value to the vGPU manager [1].
Impact
Successful exploitation can lead to data tampering, information disclosure, or denial of service. The attacker could corrupt data, read sensitive information from memory, or cause the system to crash. The compromise occurs at the host level, potentially affecting all virtual machines using the vGPU [1].
Mitigation
NVIDIA has released fixed versions of the driver. For Gentoo Linux, users should upgrade to the following versions or later: x11-drivers/nvidia-drivers-470.182.03:0/470, x11-drivers/nvidia-drivers-515.105.01:0/515, x11-drivers/nvidia-drivers-525.105.17:0/525, or x11-drivers/nvidia-drivers-530.41.03:0/530 [1]. Users of other distributions should apply the patches from NVIDIA. There is no known workaround for this vulnerability [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- NVIDIA/vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (Virtual GPU Manager)v5Range: All versions prior to and including 14.2, 13.4, and 11.9, and all versions prior to the November 2022 release
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- security.gentoo.org/glsa/202310-02mitrevendor-advisory
- nvidia.custhelp.com/app/answers/detail/a_id/5415mitre
News mentions
0No linked articles in our index yet.