VYPR
Unrated severityNVD Advisory· Published Dec 30, 2022· Updated Apr 11, 2025

CVE-2022-42261

CVE-2022-42261

Description

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where an input index is not validated, which may lead to buffer overrun, which in turn may cause data tampering, information disclosure, or denial of service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

NVIDIA vGPU Virtual GPU Manager has an unvalidated input index that leads to buffer overrun, enabling data tampering, information disclosure, or denial of service.

Vulnerability

CVE-2022-42261 is a vulnerability in the NVIDIA vGPU software, specifically in the Virtual GPU Manager (vGPU plugin). The issue is that an input index is not validated, which can lead to a buffer overrun. This affects NVIDIA vGPU versions as distributed with NVIDIA Drivers. The vulnerability is present in the vGPU plugin that manages virtual GPU instances within the host kernel [1].

Exploitation

An attacker requires local access to the system where the NVIDIA vGPU plugin is loaded. The attacker must be able to interact with the vGPU manager, potentially through a virtual machine that has access to the vGPU. By supplying an invalid index, the attacker triggers a buffer overrun. The exact sequence of steps is not detailed but involves providing an out-of-range index value to the vGPU manager [1].

Impact

Successful exploitation can lead to data tampering, information disclosure, or denial of service. The attacker could corrupt data, read sensitive information from memory, or cause the system to crash. The compromise occurs at the host level, potentially affecting all virtual machines using the vGPU [1].

Mitigation

NVIDIA has released fixed versions of the driver. For Gentoo Linux, users should upgrade to the following versions or later: x11-drivers/nvidia-drivers-470.182.03:0/470, x11-drivers/nvidia-drivers-515.105.01:0/515, x11-drivers/nvidia-drivers-525.105.17:0/525, or x11-drivers/nvidia-drivers-530.41.03:0/530 [1]. Users of other distributions should apply the patches from NVIDIA. There is no known workaround for this vulnerability [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Nvidia/vGPUllm-fuzzy
  • NVIDIA/vGPU software (Virtual GPU Manager), NVIDIA Cloud Gaming (Virtual GPU Manager)v5
    Range: All versions prior to and including 14.2, 13.4, and 11.9, and all versions prior to the November 2022 release

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.