CVE-2021-34379: High severity nvidia linux for tegra vulnerability
Published Jun 30, 2021
·Updated
Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 10 is missing. The length of an I/O buffer parameter is not checked, which might lead to memory corruption.
Affected Software
9 affected components
Nvidia Jetson Linux<32.5.1
Nvidia Jetson Agx Xavier 16gb
Nvidia Jetson Agx Xavier 32gb
Nvidia Jetson Agx Xavier 8gb
Nvidia Jetson TX2
Nvidia Jetson Tx2 4gb
Nvidia Jetson Tx2 Nx
Nvidia Jetson Tx2i
Nvidia Jetson Xavier NX
Event History
Jun 30, 2021
CVE Published
via MITRE·10:24 AM
Data Sourced
via MITRE·10:24 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2021-34379.
2
What is the severity of CVE-2021-34379?
The severity of CVE-2021-34379 is high with a CVSS score of 6.7.
3
Which software is affected by CVE-2021-34379?
The NVIDIA Jetson Linux software up to version 32.5.1 is affected by CVE-2021-34379.
4
How does CVE-2021-34379 occur?
CVE-2021-34379 occurs due to missing bounds checking in command 10 of the HDCP service TA in Trusty.
5
Is there a fix available for CVE-2021-34379?
Yes, please refer to the following link for information on how to fix CVE-2021-34379: [https://nvidia.custhelp.com/app/answers/detail/a_id/5205](https://nvidia.custhelp.com/app/answers/detail/a_id/5205).