First published: Wed Jun 30 2021(Updated: )
Trusty contains a vulnerability in the HDCP service TA where bounds checking in command 10 is missing. The length of an I/O buffer parameter is not checked, which might lead to memory corruption.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA Linux for Tegra | <32.5.1 | |
NVIDIA Jetson AGX Xavier | ||
NVIDIA Jetson AGX Xavier | ||
NVIDIA Jetson AGX Xavier | ||
NVIDIA Jetson TX2 4GB | ||
NVIDIA Jetson TX2 4GB | ||
NVIDIA Jetson TX2 NX | ||
NVIDIA Jetson TX2i | ||
NVIDIA Jetson AGX Xavier |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2021-34379.
The severity of CVE-2021-34379 is high with a CVSS score of 6.7.
The NVIDIA Jetson Linux software up to version 32.5.1 is affected by CVE-2021-34379.
CVE-2021-34379 occurs due to missing bounds checking in command 10 of the HDCP service TA in Trusty.
Yes, please refer to the following link for information on how to fix CVE-2021-34379: [https://nvidia.custhelp.com/app/answers/detail/a_id/5205](https://nvidia.custhelp.com/app/answers/detail/a_id/5205).