NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot blob_decompress function, where insufficient validation of untrusted data may allow a local attacker with elevated privileges to cause a memory buffer overflow, which may lead to code execution, limited loss of Integrity, and limited denial of service. The scope of impact can extend to other components.
2022-04-27T18:15:08.097
2024-11-21T06:56:55.917
Modified
CVSSv3.1: 4.6 (MEDIUM)
AV:L/AC:L/Au:N/C:N/I:P/A:P
3.9
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | nvidia | jetson_linux | < 32.7.2 | Yes |
Hardware | nvidia | jetson_agx_xavier | - | No |
Hardware | nvidia | jetson_tx2 | - | No |
Hardware | nvidia | jetson_tx2_nx | - | No |
Hardware | nvidia | jetson_xavier_nx | - | No |