Stack-based Buffer Overflow in NVIDIA Linux Distributions
CVE-2022-42270
7.8HIGH
Key Information:
- Vendor
- Nvidia
- Vendor
- CVE Published:
- 30 December 2022
Summary
NVIDIA Linux distributions contain a vulnerability in the nvdla_emu_task_submit function, where unvalidated input can lead to a stack-based buffer overflow in kernel code. This flaw may allow local attackers to execute malicious code, potentially leading to privilege escalation, impaired integrity, compromised confidentiality, and service disruptions.
Affected Version(s)
NVIDIA Jetson AGX Xavier Series, Jetson Xavier NX, Jetson AGX Orin Series Jetson Linux Versions 35.1 and 34.1.1
NVIDIA Jetson AGX Xavier Series, Jetson Xavier NX, Jetson AGX Orin Series Jetson Linux 32.7.2 and prior releases
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved