Description
NVIDIA TrustZone Software contains a vulnerability in the Keymaster implementation where the software reads data past the end, or before the beginning, of the intended buffer; and may lead to denial of service or information disclosure. This issue is rated as high.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
http://nvidia.custhelp.com/app/answers/detail/a_id/4631
Scores
CVSS v3
8.4
EPSS
0.0001
EPSS Percentile
3.4%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H
Details
CWE
CWE-125
Status
published
Products (2)
google/android
nvidia/shield_tv_firmware
< 6.2
Published
Mar 06, 2018
Tracked Since
Feb 18, 2026