CVE-2022-28192

MEDIUM

NVIDIA vGPU 11.0-11.8 - Use-After-Free in Virtual GPU Manager

Title source: llm
STIX 2.1

Description

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where it may lead to a use-after-free, which in turn may cause denial of service. This attack is complex to carry out because the attacker needs to have control over freeing some host side resources out of sequence, which requires elevated privileges.

References (1)

Core 1
Core References
Patch, Vendor Advisory x_refsource_misc
https://nvidia.custhelp.com/app/answers/detail/a_id/5353

Scores

CVSS v3 4.1
EPSS 0.0012
EPSS Percentile 29.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-416
Status published
Products (2)
nvidia/virtual_gpu 14.0
nvidia/virtual_gpu 11.0 - 11.8
Published May 17, 2022
Tracked Since Feb 18, 2026