CVE-2022-42262

HIGH

Nvidia Virtual Gpu < 11.11 - Out-of-Bounds Write

Title source: rule
STIX 2.1

Description

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where an input index is not validated, which may lead to buffer overrun, which in turn may cause data tampering, information disclosure, or denial of service.

References (1)

Core 1

Scores

CVSS v3 7.1
EPSS 0.0012
EPSS Percentile 31.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-120 CWE-787
Status published
Products (3)
nvidia/cloud_gaming < 525.60.12
nvidia/gpu_display_driver 470 - 470.161.03
nvidia/virtual_gpu < 11.11
Published Dec 30, 2022
Tracked Since Feb 18, 2026