SB2022120223 - Multiple vulnerabilities in NVIDIA Jetson AGX Xavier Series, Jetson Xavier NX, Jetson TX1, Jetson TX2 Series, Jetson TX2 NX, Jetson Nano and Jetson Nano 2GB
Published: December 2, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Input validation error (CVE-ID: CVE-2022-42269)
The vulnerability allows a local user to compromise the target system.
The vulnerability exists due to insufficient validation of user-supplied input in an SMC call handler. A local administrator can cause information disclosure and compromise integrity.
2) Stack-based buffer overflow (CVE-ID: CVE-2022-42270)
The vulnerability allows a local user to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in nvdla_emu_task_submit. A local user can trigger stack-based buffer overflow and execute arbitrary code on the target system with elevated privileges.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Remediation
Install update from vendor's website.