First published: Wed Apr 27 2022(Updated: )
NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where, if TFTP is enabled, a local attacker with elevated privileges can cause a memory buffer overflow, which may lead to code execution, loss of Integrity, limited denial of service, and some impact to confidentiality.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA Jetson Linux | <32.7.2 | |
NVIDIA Jetson AGX Xavier | ||
Nvidia Jetson Xavier Nx |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28194 is a vulnerability in the NVIDIA Jetson Linux Driver Package that allows a local attacker with elevated privileges to cause a memory buffer overflow, leading to potential code execution, loss of integrity, limited denial of service, and some impact to system confidentiality.
The severity of CVE-2022-28194 is high, with a severity value of 5.6.
CVE-2022-28194 affects NVIDIA Jetson Linux versions up to and including 32.7.2, where a vulnerability in the Cboot module tegrabl_cbo.c can be exploited if TFTP is enabled.
A local attacker with elevated privileges can exploit CVE-2022-28194 by leveraging the vulnerability in the Cboot module tegrabl_cbo.c and causing a memory buffer overflow when TFTP is enabled.
No, NVIDIA Jetson AGX Xavier is not affected by CVE-2022-28194.
No, Nvidia Jetson Xavier Nx is not affected by CVE-2022-28194.
To fix CVE-2022-28194, NVIDIA recommends updating to the latest version of the Jetson Linux Driver Package, which addresses the vulnerability.
You can find more information about CVE-2022-28194 on the NVIDIA customer support website.