Trusty contains a vulnerability in NVIDIA OTE protocol message parsing code, which is present in all the TAs. An incorrect bounds check can allow a local user through a malicious client to access memory from the heap in the TrustZone, which may lead to information disclosure.
2021-06-21T22:15:07.833
2024-11-21T06:10:17.770
Modified
CVSSv3.1: 5.0 (MEDIUM)
AV:L/AC:M/Au:N/C:P/I:N/A:N
3.4
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | nvidia | jetson_linux | < 32.5.1 | Yes |
Hardware | nvidia | jetson_agx_xavier_16gb | - | No |
Hardware | nvidia | jetson_agx_xavier_32gb | - | No |
Hardware | nvidia | jetson_agx_xavier_8gb | - | No |
Hardware | nvidia | jetson_tx2 | - | No |
Hardware | nvidia | jetson_tx2_4gb | - | No |
Hardware | nvidia | jetson_tx2_nx | - | No |
Hardware | nvidia | jetson_tx2i | - | No |
Hardware | nvidia | jetson_xavier_nx | - | No |
Hardware | nvidia | jetson_xavier_nx | - | No |