Trusty (the trusted OS produced by NVIDIA for Jetson devices) driver contains a vulnerability in the NVIDIA OTE protocol message parsing code where an integer overflow in a malloc() size calculation leads to a buffer overflow on the heap, which might result in information disclosure, escalation of privileges, and denial of service.
2021-06-22T22:15:08.947
2024-11-21T06:10:15.447
Modified
CVSSv3.1: 8.2 (HIGH)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | nvidia | jetson_linux | < 32.5.1 | Yes |
Hardware | nvidia | jetson_agx_xavier_16gb | - | No |
Hardware | nvidia | jetson_agx_xavier_32gb | - | No |
Hardware | nvidia | jetson_agx_xavier_8gb | - | No |
Hardware | nvidia | jetson_nano | - | No |
Hardware | nvidia | jetson_nano | - | No |
Hardware | nvidia | jetson_nano_2gb | - | No |
Hardware | nvidia | jetson_tx1 | - | No |
Hardware | nvidia | jetson_tx2 | - | No |
Hardware | nvidia | jetson_tx2_4gb | - | No |
Hardware | nvidia | jetson_tx2_nx | - | No |
Hardware | nvidia | jetson_tx2i | - | No |
Hardware | nvidia | jetson_xavier_nx | - | No |
Hardware | nvidia | jetson_xavier_nx | - | No |