Information Disclosure Vulnerability in NVIDIA Trusty for Secure Computing
CVE-2021-34389
5MEDIUM
Key Information:
- Vendor
Nvidia
- Vendor
- CVE Published:
- 21 June 2021
What is CVE-2021-34389?
NVIDIA Trusty contains a vulnerability resulting from improper parsing of the OTE protocol messages. This flaw allows local users to exploit an incorrect bounds check, potentially gaining access to sensitive heap memory within the TrustZone environment. This unauthorized access can lead to information disclosure and poses a security risk for systems running affected versions of Trusty.
Affected Version(s)
NVIDIA Jetson, TX2 series, TX2 NX, AGX Xavier series, Xavier NX All Jetson Linux versions prior to r32.5.1