Stack-based Buffer Overflow in NVIDIA Linux Distributions
CVE-2022-42270

7.8HIGH

Key Information:

Summary

NVIDIA Linux distributions contain a vulnerability in the nvdla_emu_task_submit function, where unvalidated input can lead to a stack-based buffer overflow in kernel code. This flaw may allow local attackers to execute malicious code, potentially leading to privilege escalation, impaired integrity, compromised confidentiality, and service disruptions.

Affected Version(s)

NVIDIA Jetson AGX Xavier Series, Jetson Xavier NX, Jetson AGX Orin Series Jetson Linux Versions 35.1 and 34.1.1

NVIDIA Jetson AGX Xavier Series, Jetson Xavier NX, Jetson AGX Orin Series Jetson Linux 32.7.2 and prior releases

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.