Jetson AGX Xavier / Xavier NX: Arbitrary memory R/W (PCIe controller without IOMMU)
CVSS 7.1CVE-2023-25518NVIDIA / GPU stackcurated
Impact
Arbitrary memory R/W (PCIe controller without IOMMU)
Who can reach it
Local attacker with physical access
What to do
Flash JetPack 32.7.4+; edge fleet only, not core DC
References
Related entries
- GPU Display Driver: Local privesc / data tampering (OOB write)CVE-2024-0074 · GPU Display DriverHigh
- NVIDIA vGPU software - Virtual GPU Manager (host-side vGPU plugin / nvidia.ko): The host vGPU plugin lets a guest reachCVE-2024-0128 · NVIDIA vGPU software - Virtual GPU Manager (host-side vGPU plugin / nvidia.ko)High
- GPU Display Driver: Local privesc (kernel driver buffer overflow)CVE-2024-0150 · GPU Display DriverHigh
- Linux kernel amdgpu power management (SMU/powerplay) (drm/amdgpu): A NULL pointer dereference in the amdgpu powerCVE-2024-26672 · Linux kernel amdgpu power management (SMU/powerplay) (drm/amdgpu)High
- Linux kernel amdgpu kernel driver core (drm/amdgpu): An out-of-bounds access in the amdgpu kernel driver core - aCVE-2024-27029 · Linux kernel amdgpu kernel driver core (drm/amdgpu)High
- NVIDIA/Mellanox ConnectX flow steering core (mlx5 fs_core rule tree linkage): Flow steering is what decides whichCVE-2024-35960 · NVIDIA/Mellanox ConnectX flow steering core (mlx5 fs_core rule tree linkage)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.