CVE-2021-34402
Severity CVSS v4.0:
Pending analysis
Type:
CWE-125
Out-of-bounds Read
Publication date:
18/01/2022
Last modified:
24/10/2022
Description
NVIDIA Tegra kernel driver contains a vulnerability in NVIDIA NVDEC, where a user with high privileges might be able to read from or write to a memory location that is outside the intended boundary of the buffer, which may lead to denial of service, Information disclosure, loss of Integrity, or possible escalation of privileges.
Impact
Base Score 3.x
6.70
Severity 3.x
MEDIUM
Base Score 2.0
4.60
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:nvidia:shield_experience:*:*:*:*:*:*:*:* | 9.0 (excluding) | |
cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page