CVE-2022-28193

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
27/04/2022
Last modified:
28/06/2023

Description

NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where insufficient validation of untrusted data may allow a local attacker with elevated privileges to cause a memory buffer overflow, which may lead to code execution, loss of integrity, limited denial of service, and some impact to confidentiality.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:nvidia:jetson_linux:*:*:*:*:*:*:*:* 32.7.2 (excluding)
cpe:2.3:h:nvidia:jetson_agx_xavier:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_xavier_nx:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools