CVE-2021-34372

HIGH

NVIDIA Jetson Linux < 32.5.1 - Integer Overflow to Heap Buffer Overflow in Trusty OTE Protocol Message Parsing

Title source: llm
STIX 2.1

Description

Trusty (the trusted OS produced by NVIDIA for Jetson devices) driver contains a vulnerability in the NVIDIA OTE protocol message parsing code where an integer overflow in a malloc() size calculation leads to a buffer overflow on the heap, which might result in information disclosure, escalation of privileges, and denial of service.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://nvidia.custhelp.com/app/answers/detail/a_id/5205

Scores

CVSS v3 8.2
EPSS 0.0008
EPSS Percentile 22.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Details

CWE
CWE-190
Status published
Products (1)
nvidia/jetson_linux < 32.5.1
Published Jun 22, 2021
Tracked Since Feb 18, 2026