CVE-2021-1070: High severity nvidia vibrante linux vulnerability
NVIDIA Jetson AGX Xavier Series, Jetson Xavier NX, TX1, TX2, Nano and Nano 2GB, L4T versions prior to 32.5, contains a vulnerability in the applybinaries.sh script used to install NVIDIA components into the root file system image, in which improper access control is applied, which may lead to an unprivileged user being able to modify system device tree files, leading to denial of service.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-1070?
CVE-2021-1070 is a vulnerability found in NVIDIA Jetson AGX Xavier Series, Jetson Xavier NX, TX1, TX2, Nano and Nano 2GB, L4T versions prior to 32.5.
What is the severity of CVE-2021-1070?
The severity of CVE-2021-1070 is high, with a severity value of 7.1.
Which software versions are affected by CVE-2021-1070?
NVIDIA Jetson AGX Xavier Series, Jetson Xavier NX, TX1, TX2, Nano, and Nano 2GB L4T versions prior to 32.5 are affected by CVE-2021-1070.
What is the vulnerability in CVE-2021-1070?
CVE-2021-1070 is a vulnerability in the apply_binaries.sh script used to install NVIDIA components into the root file system image, which allows improper access control.
How can I fix CVE-2021-1070?
To fix CVE-2021-1070, update your NVIDIA Jetson AGX Xavier Series, Jetson Xavier NX, TX1, TX2, Nano, and Nano 2GB to L4T version 32.5 or later.