PT-2021-13466 · Nvidia · L4T+6

Michael De Gans

·

Published

2021-01-26

·

Updated

2021-02-04

·

CVE-2021-1070

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions NVIDIA Jetson AGX Xavier Series, Jetson Xavier NX, TX1, TX2, Nano and Nano 2GB, L4T versions prior to 32.5
Description The issue is related to improper access control in the apply binaries.sh script, which is used to install NVIDIA components into the root file system image. This may allow an unprivileged user to modify system device tree files, leading to denial of service.
Recommendations For L4T versions prior to 32.5, update to version 32.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the apply binaries.sh script to prevent unprivileged users from modifying system device tree files.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-1070

Affected Products

Jetson Xavier Nx
L4T
Nvidia Jetson Agx Xavier Series
Nano
Nano 2Gb
Tx1
Tx2