7.8

CVE-2021-1106

NVIDIA Linux kernel distributions contain a vulnerability in nvmap, where writes may be allowed to read-only buffers, which may result in escalation of privileges, complete denial of service, unconstrained information disclosure, and serious data tampering of all processes on the system.

Data is provided by the National Vulnerability Database (NVD)
NvidiaJetson Linux Version >= 32.1 < 32.6.1
   NvidiaJetson Agx Xavier Version-
   NvidiaJetson Nano Version-
   NvidiaJetson Nano 2gb Version-
   NvidiaJetson Tx1 Version-
   NvidiaJetson Tx2 Version-
   NvidiaJetson Tx2 Nx Version-
   NvidiaJetson Xavier Nx Version-
NvidiaShield Experience Version < 9.0
   NvidiaShield Tv Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.11% 0.304
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
psirt@nvidia.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.