Description
NVIDIA Jetson Linux contains a vulnerability in NvGPU where error handling paths in GPU MMU mapping code fail to clean up a failed mapping attempt. A successful exploit of this vulnerability may lead to denial of service, code execution, and escalation of privileges.
Published: 2024-08-08
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-15909 NVIDIA Jetson Linux contains a vulnerability in NvGPU where error handling paths in GPU MMU mapping code fail to clean up a failed mapping attempt. A successful exploit of this vulnerability may lead to denial of service, code execution, and escalation of privileges.
History

Mon, 16 Sep 2024 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia jetson Agx Xavier 16gb
Nvidia jetson Agx Xavier 32gb
Nvidia jetson Agx Xavier 64gb
Nvidia jetson Agx Xavier 8gb
Nvidia jetson Agx Xavier Industrial
Nvidia jetson Linux
Nvidia jetson Nano 2gb
Nvidia jetson Tx1 L4t
Nvidia jetson Tx2 4gb
Nvidia jetson Tx2i
Nvidia jetson Xavier Nx 16gb
CPEs cpe:2.3:h:nvidia:jetson_agx_xavier:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_agx_xavier_16gb:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_agx_xavier_32gb:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_agx_xavier_64gb:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_agx_xavier_8gb:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_agx_xavier_industrial:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_nano:-:*:-:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_nano:-:*:developer_kit:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_nano_2gb:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_tx1_l4t:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_tx2_4gb:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_tx2i:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_xavier_nx:-:*:developer_kit:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_xavier_nx:-:*:production:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_xavier_nx_16gb:-:*:*:*:*:*:*:*
cpe:2.3:o:nvidia:jetson_linux:*:*:*:*:*:*:*:*
Vendors & Products Nvidia jetson Agx Xavier 16gb
Nvidia jetson Agx Xavier 32gb
Nvidia jetson Agx Xavier 64gb
Nvidia jetson Agx Xavier 8gb
Nvidia jetson Agx Xavier Industrial
Nvidia jetson Linux
Nvidia jetson Nano 2gb
Nvidia jetson Tx1 L4t
Nvidia jetson Tx2 4gb
Nvidia jetson Tx2i
Nvidia jetson Xavier Nx 16gb

Fri, 09 Aug 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia jetson Agx Xavier
Nvidia jetson Nano
Nvidia jetson Tx1
Nvidia jetson Tx2
Nvidia jetson Tx2 Nx
Nvidia jetson Xavier Nx
CPEs cpe:2.3:a:nvidia:jetson_agx_xavier:*:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_nano:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_tx1:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_tx2:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_tx2_nx:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_xavier_nx:-:*:*:*:*:*:*:*
Vendors & Products Nvidia
Nvidia jetson Agx Xavier
Nvidia jetson Nano
Nvidia jetson Tx1
Nvidia jetson Tx2
Nvidia jetson Tx2 Nx
Nvidia jetson Xavier Nx
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Aug 2024 16:30:00 +0000

Type Values Removed Values Added
Description NVIDIA Jetson Linux contains a vulnerability in NvGPU where error handling paths in GPU MMU mapping code fail to clean up a failed mapping attempt. A successful exploit of this vulnerability may lead to denial of service, code execution, and escalation of privileges.
Weaknesses CWE-755
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L'}


Subscriptions

Nvidia Jetson Agx Xavier Jetson Agx Xavier 16gb Jetson Agx Xavier 32gb Jetson Agx Xavier 64gb Jetson Agx Xavier 8gb Jetson Agx Xavier Industrial Jetson Linux Jetson Nano Jetson Nano 2gb Jetson Tx1 Jetson Tx1 L4t Jetson Tx2 Jetson Tx2 4gb Jetson Tx2 Nx Jetson Tx2i Jetson Xavier Nx Jetson Xavier Nx 16gb
cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2024-08-09T15:48:50.071Z

Reserved: 2023-12-02T00:42:18.437Z

Link: CVE-2024-0108

cve-icon Vulnrichment

Updated: 2024-08-09T15:42:03.427Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-08T17:15:18.473

Modified: 2024-09-16T19:27:19.833

Link: CVE-2024-0108

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses