CVE-2024-0099: NVIDIA Geforce

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

NVIDIA vGPU software for Linux contains a vulnerability in the Virtual GPU Manager, where the guest OS could cause buffer overrun in the host. A successful exploit of this vulnerability might lead to information disclosure, data tampering, escalation of privileges, and denial of service.

Affected products

  • NVIDIA Geforce: before 555.52.04 (fixed in 555.52.04); before 550.90.07 (fixed in 550.90.07); before 535.183.01 (fixed in 535.183.01); before 470.256.02 (fixed in 470.256.02)
  • NVIDIA Nvs: before 555.52.04 (fixed in 555.52.04); before 550.90.07 (fixed in 550.90.07); before 535.183.01 (fixed in 535.183.01); before 470.256.02 (fixed in 470.256.02)
  • NVIDIA Quadro: before 555.52.04 (fixed in 555.52.04); before 550.90.07 (fixed in 550.90.07); before 535.183.01 (fixed in 535.183.01); before 470.256.02 (fixed in 470.256.02)
  • NVIDIA Rtx: before 555.52.04 (fixed in 555.52.04); before 550.90.07 (fixed in 550.90.07); before 535.183.01 (fixed in 535.183.01); before 470.256.02 (fixed in 470.256.02)
  • NVIDIA Tesla: before 550.90.07 (fixed in 550.90.07); before 535.183.01 (fixed in 535.183.01); before 470.256.02 (fixed in 470.256.02)
  • NVIDIA Vgpu Software And Cloud Gaming

Published 2024-06-13. Last modified 2026-06-17.