CVE-2021-34380

HIGH

NVIDIA Jetson Linux < 32.5.1 - Out-of-bounds Write in MB2 Bootloader

Title source: llm
STIX 2.1

Description

Bootloader contains a vulnerability in NVIDIA MB2 where potential heap overflow might cause corruption of the heap metadata, which might lead to arbitrary code execution, denial of service, and information disclosure during secure boot.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://nvidia.custhelp.com/app/answers/detail/a_id/5205

Scores

CVSS v3 7.0
EPSS 0.0008
EPSS Percentile 23.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (1)
nvidia/jetson_linux < 32.5.1
Published Jun 30, 2021
Tracked Since Feb 18, 2026