SB2022120223 - Multiple vulnerabilities in NVIDIA Jetson AGX Xavier Series, Jetson Xavier NX, Jetson TX1, Jetson TX2 Series, Jetson TX2 NX, Jetson Nano and Jetson Nano 2GB



SB2022120223 - Multiple vulnerabilities in NVIDIA Jetson AGX Xavier Series, Jetson Xavier NX, Jetson TX1, Jetson TX2 Series, Jetson TX2 NX, Jetson Nano and Jetson Nano 2GB

Published: December 2, 2022

Security Bulletin ID SB2022120223
Severity
Low
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Input validation error (CVE-ID: CVE-2022-42269)

The vulnerability allows a local user to compromise the target system.

The vulnerability exists due to insufficient validation of user-supplied input in an SMC call handler. A local administrator can cause information disclosure and compromise integrity.


2) Stack-based buffer overflow (CVE-ID: CVE-2022-42270)

The vulnerability allows a local user to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in nvdla_emu_task_submit. A local user can trigger stack-based buffer overflow and execute arbitrary code on the target system with elevated privileges.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Remediation

Install update from vendor's website.