CVE-2022-28191
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2022-28191 is a vulnerability discovered in NVIDIA vGPU software, specifically affecting the Virtual GPU Manager (nvidia.ko) component. The vulnerability was disclosed on May 17, 2022, with a CVSS v3.1 base score of 5.5 (Medium severity). This security flaw affects various NVIDIA vGPU software versions across multiple platforms including Citrix Hypervisor, VMware vSphere, and Red Hat Enterprise Linux KVM (NVIDIA Bulletin).

Technical details

The vulnerability is characterized by uncontrolled resource consumption in the Virtual GPU Manager (nvidia.ko) that can be triggered by an unprivileged regular user. The CVSS vector for this vulnerability is AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H, indicating local access required, low attack complexity, low privileges required, no user interaction needed, unchanged scope, and high impact on availability (NVIDIA Bulletin).

Impact

When exploited, CVE-2022-28191 can lead to denial of service conditions in the affected systems. The vulnerability specifically impacts the availability of the system while having no direct effect on confidentiality or integrity (NVIDIA Bulletin).

Mitigation and workarounds

NVIDIA has released security updates to address this vulnerability. For vGPU software (Virtual GPU Manager), users should upgrade to version 14.1 (510.73.06), 13.3 (470.129.04), or 11.8 (450.191) depending on their branch. No alternative mitigations are provided, making the update installation critical for security (NVIDIA Bulletin).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-23745HIGH8.2
  • JavaScriptJavaScript
  • argo-workflows-fips-3.6
NoYesJan 16, 2026
CVE-2026-23535HIGH8
  • PythonPython
  • wlc
NoYesJan 16, 2026
CVE-2026-23490HIGH7.5
  • PythonPython
  • pyasn1
NoYesJan 16, 2026
CVE-2026-23643MEDIUM5.4
  • CakePHPCakePHP
  • cakephp
NoYesJan 16, 2026
CVE-2025-61873LOW2.6
  • Linux DebianLinux Debian
  • request-tracker4
NoYesJan 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management