CVE-2022-21819
published 2022-03-11CVE-2022-21819: NVIDIA distributions of Jetson Linux contain a vulnerability where an error in the IOMMU configuration may allow an unprivileged attacker with physical access…
PriorityP336high7.6CVSS 3.1
AVPACLPRNUINSCCHIHAH
EPSS
0.39%
31.7th percentile
NVIDIA distributions of Jetson Linux contain a vulnerability where an error in the IOMMU configuration may allow an unprivileged attacker with physical access to the board direct read/write access to the entire system address space through the PCI bus. Such an attack could result in denial of service, code execution, escalation of privileges, and impact to data integrity and confidentiality. The scope impact may extend to other components.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nvidia | jetson_linux | >= 32.1 < 32.7.1 | 32.7.1 |
CVSS provenance
nvdv3.17.6HIGHCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
NVIDIA Jetson AGX Xavier on Linux IOMMU Configuration permission assignment (EUVD-2022-26979)
vuldb·2026-04-28·CVSS 7.6
CVE-2022-21819 [HIGH] NVIDIA Jetson AGX Xavier on Linux IOMMU Configuration permission assignment (EUVD-2022-26979)
A vulnerability has been found in NVIDIA Jetson AGX Xavier, Jetson Xavier NX, Jetson TX1, Jetson TX2 and Jetson Nano on Linux and classified as problematic. This affects an unknown part of the component IOMMU Configuration. Performing a manipulation results in incorrect permission assignment.
This vulnerability is reported as CVE-2022-21819. The attack may be carried out on the physical device. No exploit exists.
GHSA
GHSA-5q8q-7qqw-cmj3: NVIDIA distributions of Jetson Linux contain a vulnerability where an error in the IOMMU configuration may allow an unprivileged attacker with physica
ghsa_unreviewed·2022-03-12
CVE-2022-21819 [HIGH] CWE-732 GHSA-5q8q-7qqw-cmj3: NVIDIA distributions of Jetson Linux contain a vulnerability where an error in the IOMMU configuration may allow an unprivileged attacker with physica
NVIDIA distributions of Jetson Linux contain a vulnerability where an error in the IOMMU configuration may allow an unprivileged attacker with physical access to the board direct read/write access to the entire system address space through the PCI bus. Such an attack could result in denial of service, code execution, escalation of privileges, and impact to data integrity and confidentiality. The scope impact may extend to other components.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://nvidia.custhelp.com/app/answers/detail/a_id/5321https://www.thegoodpenguin.co.uk/blog/pcie-dma-attack-against-a-secured-jetson-nano-cve-2022-21819/https://nvidia.custhelp.com/app/answers/detail/a_id/5321https://www.thegoodpenguin.co.uk/blog/pcie-dma-attack-against-a-secured-jetson-nano-cve-2022-21819/
2022-03-11
Published