NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller, which may allow a user with elevated privileges to instantiate a DMA write operation only within a specific time window timed to corrupt code execution, which may impact confidentiality, integrity, or availability. The scope impact may extend to other components.
Metrics
No CVSS v4.0
Attack Vector Local
Attack Complexity High
Privileges Required High
Scope Changed
Confidentiality Impact High
Integrity Impact High
Availability Impact High
User Interaction None
No CVSS v3.0
Access Vector Local
Access Complexity Medium
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete
AV:L/AC:M/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
Vendors | Products |
---|---|
Linux |
|
Microsoft |
|
Nvidia |
|
Configuration 1 [-]
AND |
|
No data.
References
Link | Providers |
---|---|
https://nvidia.custhelp.com/app/answers/detail/a_id/5263 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: nvidia
Published: 2021-11-20T14:55:23
Updated: 2024-08-03T19:05:55.701Z
Reserved: 2021-02-09T00:00:00
Link: CVE-2021-23217
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-11-20T15:15:07.890
Modified: 2024-11-21T05:51:23.477
Link: CVE-2021-23217
Redhat
No data.