CVE-2021-34372: Buffer Overflow
Published Jun 22, 2021
·Updated
Trusty (the trusted OS produced by NVIDIA for Jetson devices) driver contains a vulnerability in the NVIDIA OTE protocol message parsing code where an integer overflow in a malloc() size calculation leads to a buffer overflow on the heap, which might result in information disclosure, escalation of privileges, and denial of service.
Affected Software
14 affected components
Nvidia Jetson Linux<32.5.1
Nvidia Jetson Agx Xavier 16gb
Nvidia Jetson Agx Xavier 32gb
Nvidia Jetson Agx Xavier 8gb
Nvidia Jetson Nano
Nvidia Jetson Nano
Nvidia Jetson Nano 2gb
Nvidia Jetson TX1
Nvidia Jetson TX2
Nvidia Jetson Tx2 4gb
Nvidia Jetson Tx2 Nx
Nvidia Jetson Tx2i
Nvidia Jetson Xavier NX
Nvidia Jetson Xavier NX
Event History
Jun 22, 2021
CVE Published
via MITRE·09:25 PM
Data Sourced
via MITRE·09:25 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-34372?
CVE-2021-34372 is a vulnerability in the Trusty driver produced by NVIDIA for Jetson devices.
2
What is the severity of CVE-2021-34372?
CVE-2021-34372 has a severity score of 7.8 (high).
3
Which software is affected by CVE-2021-34372?
The NVIDIA Jetson Linux up to version 32.5.1 is affected by CVE-2021-34372.
4
How does CVE-2021-34372 affect the system?
CVE-2021-34372 can result in information disclosure and escalation of privilege.
5
How can I fix CVE-2021-34372?
To fix CVE-2021-34372, update to a version of NVIDIA Jetson Linux that is higher than 32.5.1.