CVE-2021-1061
Last modified
CVE-2021-1061 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which a race condition may cause the vGPU plugin to continue using a previously validated resource that has since changed, which may lead to denial of service or information disclosure. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
NVIDIA vGPU manager contains a vulnerability in the vGPU plugin, in which a race condition may cause the vGPU plugin to continue using a previously validated resource that has since changed, which may lead to denial of service or information disclosure. This affects vGPU version 8.x (prior to 8.6) and version 11.0 (prior to 11.3).
Metrics
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nvidia | Virtual Gpu Manager | >= 8.0, < 8.6 |
| Nvidia | Virtual Gpu Manager | >= 11.0, < 11.3 |
References
- https://nvidia.custhelp.com/app/answers/detail/a_id/5142Vendor Advisory
- https://nvidia.custhelp.com/app/answers/detail/a_id/5142Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-1061?
How severe is CVE-2021-1061?
How do I fix CVE-2021-1061?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-1055NVIDIA GPU Display Driver for Windows, all versions, contain…5.3
- CVE-2021-1056NVIDIA GPU Display Driver for Linux, all versions, contains …7.1
- CVE-2021-1057NVIDIA Virtual GPU Manager NVIDIA vGPU manager contains a vu…7.8
- CVE-2021-1058NVIDIA vGPU software contains a vulnerability in the guest k…7.1
- CVE-2021-1059NVIDIA vGPU manager contains a vulnerability in the vGPU plu…7.8
- CVE-2021-1060NVIDIA vGPU software contains a vulnerability in the guest k…7.1
- CVE-2021-1062NVIDIA vGPU manager contains a vulnerability in the vGPU plu…7.1
- CVE-2021-1063NVIDIA vGPU manager contains a vulnerability in the vGPU plu…7.8
- CVE-2021-1064NVIDIA vGPU manager contains a vulnerability in the vGPU plu…7.1
- CVE-2021-1065NVIDIA vGPU manager contains a vulnerability in the vGPU plu…7.1
- CVE-2021-1066NVIDIA vGPU manager contains a vulnerability in the vGPU plu…5.5
- CVE-2021-1067NVIDIA SHIELD TV, all versions prior to 8.2.2, contains a vu…6.8
Are you affected by CVE-2021-1061?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
