NVIDIA Jetson Linux contains a vulnerability in NvGPU where error handling paths in GPU MMU mapping code fail to clean up a failed mapping attempt. A successful exploit of this vulnerability may lead to denial of service, code execution, and escalation of privileges.

Project Subscriptions

Vendors Products
Jetson Agx Xavier Subscribe
Jetson Agx Xavier 16gb Subscribe
Jetson Agx Xavier 32gb Subscribe
Jetson Agx Xavier 64gb Subscribe
Jetson Agx Xavier 8gb Subscribe
Jetson Agx Xavier Industrial Subscribe
Jetson Linux Subscribe
Jetson Nano Subscribe
Jetson Nano 2gb Subscribe
Jetson Tx1 Subscribe
Jetson Tx1 L4t Subscribe
Jetson Tx2 Subscribe
Jetson Tx2 4gb Subscribe
Jetson Tx2 Nx Subscribe
Jetson Tx2i Subscribe
Jetson Xavier Nx Subscribe
Jetson Xavier Nx 16gb Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2024-15909 NVIDIA Jetson Linux contains a vulnerability in NvGPU where error handling paths in GPU MMU mapping code fail to clean up a failed mapping attempt. A successful exploit of this vulnerability may lead to denial of service, code execution, and escalation of privileges.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 16 Sep 2024 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia jetson Agx Xavier 16gb
Nvidia jetson Agx Xavier 32gb
Nvidia jetson Agx Xavier 64gb
Nvidia jetson Agx Xavier 8gb
Nvidia jetson Agx Xavier Industrial
Nvidia jetson Linux
Nvidia jetson Nano 2gb
Nvidia jetson Tx1 L4t
Nvidia jetson Tx2 4gb
Nvidia jetson Tx2i
Nvidia jetson Xavier Nx 16gb
CPEs cpe:2.3:h:nvidia:jetson_agx_xavier:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_agx_xavier_16gb:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_agx_xavier_32gb:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_agx_xavier_64gb:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_agx_xavier_8gb:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_agx_xavier_industrial:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_nano:-:*:-:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_nano:-:*:developer_kit:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_nano_2gb:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_tx1_l4t:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_tx2_4gb:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_tx2i:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_xavier_nx:-:*:developer_kit:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_xavier_nx:-:*:production:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_xavier_nx_16gb:-:*:*:*:*:*:*:*
cpe:2.3:o:nvidia:jetson_linux:*:*:*:*:*:*:*:*
Vendors & Products Nvidia jetson Agx Xavier 16gb
Nvidia jetson Agx Xavier 32gb
Nvidia jetson Agx Xavier 64gb
Nvidia jetson Agx Xavier 8gb
Nvidia jetson Agx Xavier Industrial
Nvidia jetson Linux
Nvidia jetson Nano 2gb
Nvidia jetson Tx1 L4t
Nvidia jetson Tx2 4gb
Nvidia jetson Tx2i
Nvidia jetson Xavier Nx 16gb

Fri, 09 Aug 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia jetson Agx Xavier
Nvidia jetson Nano
Nvidia jetson Tx1
Nvidia jetson Tx2
Nvidia jetson Tx2 Nx
Nvidia jetson Xavier Nx
CPEs cpe:2.3:a:nvidia:jetson_agx_xavier:*:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_nano:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_tx1:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_tx2:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_tx2_nx:-:*:*:*:*:*:*:*
cpe:2.3:h:nvidia:jetson_xavier_nx:-:*:*:*:*:*:*:*
Vendors & Products Nvidia
Nvidia jetson Agx Xavier
Nvidia jetson Nano
Nvidia jetson Tx1
Nvidia jetson Tx2
Nvidia jetson Tx2 Nx
Nvidia jetson Xavier Nx
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Aug 2024 16:30:00 +0000

Type Values Removed Values Added
Description NVIDIA Jetson Linux contains a vulnerability in NvGPU where error handling paths in GPU MMU mapping code fail to clean up a failed mapping attempt. A successful exploit of this vulnerability may lead to denial of service, code execution, and escalation of privileges.
Weaknesses CWE-755
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2024-08-09T15:48:50.071Z

Reserved: 2023-12-02T00:42:18.437Z

Link: CVE-2024-0108

cve-icon Vulnrichment

Updated: 2024-08-09T15:42:03.427Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-08T17:15:18.473

Modified: 2024-09-16T19:27:19.833

Link: CVE-2024-0108

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses