Home

Description

NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause heap memory access after the memory is freed. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, or information disclosure.

PUBLISHED Reserved 2025-04-15 | Published 2026-01-28 | Updated 2026-01-29 | Assigner nvidia




HIGH: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-416 Use After Free

Product status

Default status
unaffected

All driver versions prior to 590.48.01
affected

Default status
unaffected

All driver versions prior to 580.126.09
affected

Default status
unaffected

All driver versions prior to 570.211.01
affected

Default status
unaffected

All driver versions prior to 535.288.01
affected

Default status
unaffected

All driver versions prior to 590.48.01
affected

Default status
unaffected

All driver versions prior to 580.126.09
affected

Default status
unaffected

All driver versions prior to 570.211.01
affected

Default status
unaffected

All driver versions prior to 535.288.01
affected

Default status
unaffected

All driver versions prior to 590.48.01
affected

Default status
unaffected

All driver versions prior to 580.126.09
affected

Default status
unaffected

All driver versions prior to 570.211.01
affected

Default status
unaffected

All driver versions prior to 535.288.01
affected

Default status
unaffected

580.105.06(All versions prior to and including vGPU software 19.3)
affected

Default status
unaffected

570.195.02(All versions prior to and including vGPU software 18.5)
affected

Default status
unaffected

535.274.03(All versions prior to and including vGPU software 16.13)
affected

References

nvd.nist.gov/vuln/detail/CVE-2025-33220

www.cve.org/CVERecord?id=CVE-2025-33220

nvidia.custhelp.com/app/answers/detail/a_id/5747

cve.org (CVE-2025-33220)

nvd.nist.gov (CVE-2025-33220)

Download JSON