CVE-2022-28193
5.6
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L
Exploitability: 0.8 / Impact: 4.7
Source: NVD
Description
NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where insufficient validation of untrusted data may allow a local attacker with elevated privileges to cause a memory buffer overflow, which may lead to code execution, loss of integrity, limited denial of service, and some impact to confidentiality.
Affected (1)
Products: Nvidia: Jetson Linux
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 32.7.2 |
| Running on/with | Platform Versions |
|---|---|
Nvidia Jetson Agx Xavier | All versions |
Nvidia Jetson Xavier Nx | All versions |
Related CWEs
CWE-20
Improper Input Validation
The product receives input or data, but it does
not validate or incorrectly validates that the input has the
properties that are required to process the data safely and
correctly.
CWE-787
Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.