7.8

CVE-2021-1106

NVIDIA Linux kernel distributions contain a vulnerability in nvmap, where writes may be allowed to read-only buffers, which may result in escalation of privileges, complete denial of service, unconstrained information disclosure, and serious data tampering of all processes on the system.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NvidiaJetson Linux Version >= 32.1 < 32.6.1
   NvidiaJetson Agx Xavier Version-
   NvidiaJetson Nano Version-
   NvidiaJetson Nano 2gb Version-
   NvidiaJetson Tx1 Version-
   NvidiaJetson Tx2 Version-
   NvidiaJetson Tx2 Nx Version-
   NvidiaJetson Xavier Nx Version-
NvidiaShield Experience Version < 9.0
   NvidiaShield Tv Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.11% 0.304
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
psirt@nvidia.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.