CVE-2024-0108
HIGHDescription
NVIDIA Jetson Linux contains a vulnerability in NvGPU where error handling paths in GPU MMU mapping code fail to clean up a failed mapping attempt. A successful exploit of this vulnerability may lead to denial of service, code execution, and escalation of privileges.
Is your site exposed to CVE-2024-0108?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| nvidia | jetson_linux |
| nvidia | jetson_agx_xavier |
| nvidia | jetson_agx_xavier_16gb |
| nvidia | jetson_agx_xavier_32gb |
| nvidia | jetson_agx_xavier_64gb |
| nvidia | jetson_agx_xavier_8gb |
| nvidia | jetson_agx_xavier_industrial |
| nvidia | jetson_nano |
| nvidia | jetson_nano |
| nvidia | jetson_nano |
| nvidia | jetson_nano_2gb |
| nvidia | jetson_tx1 |
| nvidia | jetson_tx1_l4t |
| nvidia | jetson_tx2 |
| nvidia | jetson_tx2_4gb |
| nvidia | jetson_tx2_nx |
| nvidia | jetson_tx2i |
| nvidia | jetson_xavier_nx |
| nvidia | jetson_xavier_nx |
| nvidia | jetson_xavier_nx |
| nvidia | jetson_xavier_nx_16gb |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2024-0108? +
How severe is CVE-2024-0108? +
What products are affected by CVE-2024-0108? +
How do I check if I'm vulnerable to CVE-2024-0108? +
Related Vulnerabilities
A denial-of-service vulnerability exists in the affected products. The vulnerability could allow a remote, non-privileged user to send malicious requests …
Tonic is a native gRPC client & server implementation with async/await support. When using tonic::transport::Server there is a remote DoS …
A security issue exists within the Studio 5000 Logix Designer add-on profile (AOP) for the ArmorStart Classic distributed motor controller, …
loona is an experimental, HTTP/1.1 and HTTP/2 implementation in Rust on top of io-uring. `loona-hpack` suffers from the same vulnerability …
Team ENVY, a Security Research TEAM has found a flaw that allows for a remote code execution on the NVR. …
Routinator exits on any error when accepting incoming HTTP or RTR connections, including ones it can recover from such as …