Integer Overflow Vulnerability in NVIDIA Jetson Linux Driver Package
CVE-2022-28195
5.7MEDIUM
Key Information:
- Vendor
Nvidia
- Vendor
- CVE Published:
- 27 April 2022
What is CVE-2022-28195?
The NVIDIA Jetson Linux Driver Package presents a vulnerability in the Cboot ext4_read_file function due to insufficient validation of untrusted data. This flaw can be exploited by local attackers with high privileges, potentially causing an integer overflow. The impact of this issue may lead to unauthorized code execution, privilege escalation, limited denial of service, and threats to confidentiality and integrity of the system. The ramifications of this vulnerability can extend to other system components, emphasizing the importance of prompt remediation.
Affected Version(s)
Jetson AGX Xavier series, Jetson Xavier NX All 32.x versions prior to 32.7.2