CVE-2021-34380

Severity
7.8HIGH
EPSS
0.1%
top 76.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 30
Latest updateMay 24

Description

Bootloader contains a vulnerability in NVIDIA MB2 where potential heap overflow might cause corruption of the heap metadata, which might lead to arbitrary code execution, denial of service, and information disclosure during secure boot.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Affected Packages1 packages

NVDnvidia/jetson_linux< 32.5.1

🔴Vulnerability Details

2
GHSA
GHSA-86x3-973x-2r5r: Bootloader contains a vulnerability in NVIDIA MB2 where potential heap overflow might cause corruption of the heap metadata, which might lead to arbit2022-05-24
CVEList
CVE-2021-34380: Bootloader contains a vulnerability in NVIDIA MB2 where potential heap overflow might cause corruption of the heap metadata, which might lead to arbit2021-06-30
CVE-2021-34380 (HIGH CVSS 7.8) | Bootloader contains a vulnerability | cvebase.io