HIGH · 7.0

CVE-2021-34380

Bootloader contains a vulnerability in NVIDIA MB2 where potential heap overflow might cause corruption of the heap metadata, which might lead to arbitrary code execution, denial of service, and inform...

Vulnerability Description

Bootloader contains a vulnerability in NVIDIA MB2 where potential heap overflow might cause corruption of the heap metadata, which might lead to arbitrary code execution, denial of service, and information disclosure during secure boot.

CVSS Score

7.0

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
NvidiaJetson Linux< 32.5.1
NvidiaJetson Agx Xavier 16Gb-
NvidiaJetson Agx Xavier 32Gb-
NvidiaJetson Agx Xavier 8Gb-
NvidiaJetson Tx2-
NvidiaJetson Tx2 4Gb-
NvidiaJetson Tx2 Nx-
NvidiaJetson Tx2I-
NvidiaJetson Xavier Nx-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-34380?

CVE-2021-34380 is a vulnerability with a CVSS score of 7.0 (HIGH). Bootloader contains a vulnerability in NVIDIA MB2 where potential heap overflow might cause corruption of the heap metadata, which might lead to arbitrary code execution, denial of service, and inform...

How severe is CVE-2021-34380?

CVE-2021-34380 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-34380?

Check the references section above for vendor advisories and patch information. Affected products include: Nvidia Jetson Linux, Nvidia Jetson Agx Xavier 16Gb, Nvidia Jetson Agx Xavier 32Gb, Nvidia Jetson Agx Xavier 8Gb, Nvidia Jetson Tx2.