HIGH
NVIDIA Jetson Linux contains a vulnerability in NvGPU where error handling paths in GPU MMU mapping code fail to clean up a failed mapping attempt
Published Aug 8, 2024
8.8
HIGHCVSS 3.1
EPSS 0.23%
Description
NVIDIA Jetson Linux contains a vulnerability in NvGPU where error handling paths in GPU MMU mapping code fail to clean up a failed mapping attempt. A successful exploit of this vulnerability may lead to denial of service, code execution, and escalation of privileges.
Affected products
-
- Version All versions prior to and including 32.7.4StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| NVIDIA | n/a | unaffected |
|
AND
- < 32.7.5
Running on/with
OR
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
-
- Version 0StatusaffectedConstraints<=32.7.4
- Version
-
- Version 0StatusaffectedConstraints<=32.7.4
- Version
-
- Version 0StatusaffectedConstraints<=32.7.4
- Version
-
- Version 0StatusaffectedConstraints<=32.7.4
- Version
-
- Version 0StatusaffectedConstraints<=32.7.4
- Version
-
- Version 0StatusaffectedConstraints<=32.7.4
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| NVIDIA | Jetson Agx Xavier | n/a |
| ||||||
| NVIDIA | Jetson Nano | n/a |
| ||||||
| NVIDIA | Jetson Tx1 | n/a |
| ||||||
| NVIDIA | Jetson Tx2 | n/a |
| ||||||
| NVIDIA | Jetson Tx2 NX | n/a |
| ||||||
| NVIDIA | Jetson Xavier NX | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-15909 Advisory
- https://nvidia.custhelp.com/app/answers/detail/a_id/5555 Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-15909 | Advisory | |
| https://nvidia.custhelp.com/app/answers/detail/a_id/5555 | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner nvidia
Published Aug 8, 2024
Updated Aug 9, 2024
Reserved Dec 2, 2023
Link CVE-2024-0108
CISA Vulnrichment
Updated Aug 9, 2024
ENISA EUVD
EUVD-2024-15909 Assigner nvidia
Published Aug 8, 2024
Updated Aug 9, 2024
Exploited since n/a
Link EUVD-2024-15909