CVE-2021-34389: Medium severity nvidia linux for tegra vulnerability
Published Jun 21, 2021
·Updated
Trusty contains a vulnerability in NVIDIA OTE protocol message parsing code, which is present in all the TAs. An incorrect bounds check can allow a local user through a malicious client to access memory from the heap in the TrustZone, which may lead to information disclosure.
Affected Software
10 affected components
Nvidia Jetson Linux<32.5.1
Nvidia Jetson Agx Xavier 16gb
Nvidia Jetson Agx Xavier 32gb
Nvidia Jetson Agx Xavier 8gb
Nvidia Jetson TX2
Nvidia Jetson Tx2 4gb
Nvidia Jetson Tx2 Nx
Nvidia Jetson Tx2i
Nvidia Jetson Xavier NX
Nvidia Jetson Xavier NX
Event History
Jun 21, 2021
CVE Published
via MITRE·09:35 PM
Data Sourced
via MITRE·09:35 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2021-34389.
2
What is the description of CVE-2021-34389?
CVE-2021-34389 is a vulnerability in Trusty that allows a local user to access memory from the heap in the TrustZone, leading to potential information disclosure.
3
What software is affected by CVE-2021-34389?
The affected software includes NVIDIA Jetson Linux versions up to 32.5.1.
4
What is the severity level of CVE-2021-34389?
The severity level of CVE-2021-34389 is medium.
5
How can I fix CVE-2021-34389?
To fix CVE-2021-34389, it is recommended to update to the latest version of NVIDIA Jetson Linux.