VendorsNVIDIAjetson_linuxall versions
Vulnerabilities

NVIDIA Jetson Linux

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

49CVEs
CVE-2021-1113
NVIDIA camera firmware contains a difficult to exploit vulnerability where a highly privileged attacker can cause unauthorized modification to camera resources, which may result in complete denial of service and partial loss of data integrity for all clients.
Published 2021-08-11 · Modified
5.4EPSS 0.002
CVE-2021-34389
Trusty contains a vulnerability in NVIDIA OTE protocol message parsing code, which is present in all the TAs. An incorrect bounds check can allow a local user through a malicious client to access memory from the heap in the TrustZone, which may lead to information disclosure.
Published 2021-06-21 · Modified
5.0EPSS 0.003
CVE-2022-28197
NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot ext4_mount function, where Insufficient validation of untrusted data may allow a highly privileged local attacker to cause an integer overflow. This difficult-to-exploit vulnerability may lead to code execution, escalation of privileges, limited denial of service, and some impact to confidentiality and integrity. The scope of impact can extend to other components.
Published 2022-04-27 · Modified
5.0EPSS 0.002
CVE-2021-1114
NVIDIA Linux kernel distributions contain a vulnerability in the kernel crypto node, where use after free may lead to complete denial of service.
Published 2021-08-11 · Modified
4.9EPSS 0.002
CVE-2022-28196
NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot blob_decompress function, where insufficient validation of untrusted data may allow a local attacker with elevated privileges to cause a memory buffer overflow, which may lead to code execution, limited loss of Integrity, and limited denial of service. The scope of impact can extend to other components.
Published 2022-04-27 · Modified
4.6EPSS 0.002
CVE-2021-34395
Trusty TLK contains a vulnerability in its access permission settings where it does not properly restrict access to a resource from a user with local privileges, which might lead to limited information disclosure, a low risk of modifcations to data, and limited denial of service.
Published 2021-06-22 · Modified
4.6EPSS 0.002
CVE-2021-34393
Trusty contains a vulnerability in TSEC TA which deserializes the incoming messages even though the TSEC TA does not expose any command. This vulnerability might allow an attacker to exploit the deserializer to impact code execution, causing information disclosure.
Published 2021-06-22 · Modified
4.4EPSS 0.003
CVE-2021-34396
Bootloader contains a vulnerability in access permission settings where unauthorized software may be able to overwrite NVIDIA MB2 code, which would result in limited denial of service.
Published 2021-06-22 · Modified
3.0EPSS 0.002
CVE-2021-34397
Bootloader contains a vulnerability in NVIDIA MB2, which may cause free-the-wrong-heap, which may lead to limited denial of service.
Published 2021-06-22 · Modified
2.3EPSS 0.002
← Prev2 / 2