CVE-2021-23219
published 2021-11-20CVE-2021-23219: NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller, which may allow a user with elevated privileges to access protected…
PriorityP415medium4.1CVSS 3.1
AVLACHPRHUINSUCHINAN
EPSS
0.20%
10.5th percentile
NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller, which may allow a user with elevated privileges to access protected information by identifying, exploiting, and loading vulnerable microcode. Such an attack may lead to information disclosure.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gnu | glibc | >= 0 < 2.23-0ubuntu11.3+esm1 | 2.23-0ubuntu11.3+esm1 |
| nvidia | nvidia_gpu_and_tegra_hardware | — | — |
CVSS provenance
nvdv3.14.1MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2g6g-729w-5726: NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to access protec
ghsa_unreviewed·2022-05-24
CVE-2021-23219 [MEDIUM] GHSA-2g6g-729w-5726: NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to access protec
NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to access protected information, which may lead to information disclosure.
OSV
glibc vulnerabilities
osv·2022-03-07·CVSS 7.8
CVE-2021-3999 glibc vulnerabilities
glibc vulnerabilities
USN-5310-1 fixed several vulnerabilities in GNU. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that the GNU C library getcwd function incorrectly
handled buffers. An attacker could use this issue to cause the GNU C
Library to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2021-3999)
It was discovered that the GNU C Library sunrpc module incorrectly handled
buffer lengths. An attacker could possibly use this issue to cause the GNU
C Library to crash, resulting in a denial of service. (CVE-2022-23218,
CVE-2022-23219)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-11-20
Published