6.1

CVE-2024-0115

NVIDIA CV-CUDA for Ubuntu 20.04, Ubuntu 22.04, and Jetpack contains a vulnerability in Python APIs where a user may cause an uncontrolled resource consumption issue by a long running CV-CUDA Python process. A successful exploit of this vulnerability may lead to denial of service and data loss.

Data is provided by the National Vulnerability Database (NVD)
NvidiaCv-cuda Version0.1.0 Updateprealpha
   NvidiaJetpack Software Development Kit Version-
   CanonicalUbuntu Linux Version20.04 SwEditionlts
   CanonicalUbuntu Linux Version22.04 SwEditionlts
NvidiaCv-cuda Version0.2.0 Updatealpha
   NvidiaJetpack Software Development Kit Version-
   CanonicalUbuntu Linux Version20.04 SwEditionlts
   CanonicalUbuntu Linux Version22.04 SwEditionlts
NvidiaCv-cuda Version0.2.1 Updatealpha
   NvidiaJetpack Software Development Kit Version-
   CanonicalUbuntu Linux Version20.04 SwEditionlts
   CanonicalUbuntu Linux Version22.04 SwEditionlts
NvidiaCv-cuda Version0.3.0 Updatebeta
   NvidiaJetpack Software Development Kit Version-
   CanonicalUbuntu Linux Version20.04 SwEditionlts
   CanonicalUbuntu Linux Version22.04 SwEditionlts
NvidiaCv-cuda Version0.3.1 Updatebeta
   NvidiaJetpack Software Development Kit Version-
   CanonicalUbuntu Linux Version20.04 SwEditionlts
   CanonicalUbuntu Linux Version22.04 SwEditionlts
NvidiaCv-cuda Version0.4.0 Updatebeta
   NvidiaJetpack Software Development Kit Version-
   CanonicalUbuntu Linux Version20.04 SwEditionlts
   CanonicalUbuntu Linux Version22.04 SwEditionlts
NvidiaCv-cuda Version0.5.0 Updatebeta
   NvidiaJetpack Software Development Kit Version-
   CanonicalUbuntu Linux Version20.04 SwEditionlts
   CanonicalUbuntu Linux Version22.04 SwEditionlts
NvidiaCv-cuda Version0.6.0 Updatebeta
   NvidiaJetpack Software Development Kit Version-
   CanonicalUbuntu Linux Version20.04 SwEditionlts
   CanonicalUbuntu Linux Version22.04 SwEditionlts
NvidiaCv-cuda Version0.7.0 Updatebeta
   NvidiaJetpack Software Development Kit Version-
   CanonicalUbuntu Linux Version20.04 SwEditionlts
   CanonicalUbuntu Linux Version22.04 SwEditionlts
NvidiaCv-cuda Version0.8.0 Updatebeta
   NvidiaJetpack Software Development Kit Version-
   CanonicalUbuntu Linux Version20.04 SwEditionlts
   CanonicalUbuntu Linux Version22.04 SwEditionlts
NvidiaCv-cuda Version0.9.0 Updatebeta
   NvidiaJetpack Software Development Kit Version-
   CanonicalUbuntu Linux Version20.04 SwEditionlts
   CanonicalUbuntu Linux Version22.04 SwEditionlts
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.08% 0.243
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.1 1.8 4.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
psirt@nvidia.com 6.1 1.8 4.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.