CVE-2022-42270
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
NVIDIA distributions of Linux contain a vulnerability in nvdla_emu_task_submit, where unvalidated input may allow a local attacker to cause stack-based buffer overflow in kernel code, which may lead to escalation of privileges, compromised integrity and confidentiality, and denial of service.
Affected (1)
Products: Nvidia: Jetson Linux
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 32.7.2 |
| Running on/with | Platform Versions |
|---|---|
Nvidia Jetson Agx Xavier | All versions |
Nvidia Jetson Agx Xavier 16gb | All versions |
Nvidia Jetson Agx Xavier 32gb | All versions |
Nvidia Jetson Agx Xavier 64gb | All versions |
Nvidia Jetson Agx Xavier 8gb | All versions |
Nvidia Jetson Agx Xavier Industrial | All versions |
Nvidia Jetson Xavier Nx | All versions |
Nvidia Jetson Xavier Nx 16gb | All versions |
Related CWEs
CWE-121
Stack-based Buffer Overflow
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
CWE-787
Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.