First published: Mon Jun 21 2021(Updated: )
Bootloader contains a vulnerability in NVIDIA TegraBoot where a potential heap overflow might allow an attacker to control all the RAM after the heap block, leading to denial of service or code execution.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA Linux for Tegra | <32.5.1 | |
NVIDIA Jetson AGX Xavier | ||
NVIDIA Jetson AGX Xavier | ||
NVIDIA Jetson AGX Xavier | ||
NVIDIA Jetson Nano 2GB | ||
NVIDIA Jetson Nano 2GB | ||
NVIDIA Jetson Nano | ||
NVIDIA Jetson TX1 L4T | ||
NVIDIA Jetson TX2 4GB | ||
NVIDIA Jetson TX2 | ||
NVIDIA Jetson TX2 NX | ||
NVIDIA Jetson TX2i | ||
NVIDIA Jetson AGX Xavier | ||
NVIDIA Jetson AGX Xavier |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-34388 is a vulnerability in NVIDIA TegraBoot where a potential heap overflow might allow an attacker to control all the RAM after the heap block, leading to denial of service or code execution.
The affected software is NVIDIA Jetson Linux up to version 32.5.1.
CVE-2021-34388 has a severity rating of 7.8 (high).
To fix CVE-2021-34388, users should update to a version of NVIDIA TegraBoot that addresses the heap overflow vulnerability.
More information about CVE-2021-34388 can be found at the following link: [https://nvidia.custhelp.com/app/answers/detail/a_id/5205](https://nvidia.custhelp.com/app/answers/detail/a_id/5205)