CVE-2021-1111

MEDIUM

Jetson Linux 32.1-32.6.1 - Buffer Overflow in NV3P Server via USB Physical Access

Title source: llm
STIX 2.1

Description

Bootloader contains a vulnerability in the NV3P server where any user with physical access through USB can trigger an incorrect bounds check, which may lead to buffer overflow, resulting in limited information disclosure, limited data integrity, and denial of service across all components.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://nvidia.custhelp.com/app/answers/detail/a_id/5216

Scores

CVSS v3 6.7
EPSS 0.0028
EPSS Percentile 19.8%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H

Details

CWE
CWE-119 CWE-125
Status published
Products (1)
nvidia/jetson_linux 32.1 - 32.6.1
Published Aug 11, 2021
Tracked Since Feb 18, 2026