Rewterz Threat Advisory –CVE-2021-1593 – Cisco Packet Tracer for Windows DLL Injection Vulnerability
August 5, 2021Rewterz Threat Alert – FormBook Malware – Fresh IOCs
August 5, 2021Rewterz Threat Advisory –CVE-2021-1593 – Cisco Packet Tracer for Windows DLL Injection Vulnerability
August 5, 2021Rewterz Threat Alert – FormBook Malware – Fresh IOCs
August 5, 2021Severity
High
Analysis Summary
CVE-2021-1106
NVIDIA Linux kernel distributions contain a vulnerability in nvmap, where writes may be allowed to read-only buffers, which may result in escalation of privileges, complete denial of service, unconstrained information disclosure, and serious data tampering of all processes on the system.
CVE-2021-1107
NVIDIA Linux kernel distributions contain a vulnerability in nvmap NVMAP_IOC_WRITE* paths, where improper access controls may lead to code execution, complete denial of service, and seriously compromised integrity of all system components.
CVE-2021-1108
NVIDIA Linux kernel distributions contain a vulnerability in FuSa Capture (VI/ISP), where integer underflow due to lack of input validation may lead to complete denial of service, partial integrity, and serious confidentiality loss for all processes in the system.
CVE-2021-1109
NVIDIA camera firmware contains a multistep, timing-related vulnerability where an unauthorized modification by camera resources may result in loss of data integrity or denial of service across several streams.
CVE-2021-1110
NVIDIA Linux kernel distributions on Jetson Xavier contain a vulnerability in camera firmware where a user can change input data after validation, which may lead to complete denial of service and serious data corruption of all kernel components.
CVE-2021-1111
Bootloader contains a vulnerability in the NV3P server where any user with physical access through USB can trigger an incorrect bounds check, which may lead to buffer overflow, resulting in limited information disclosure, limited data integrity, and information disclosure across all components.
CVE-2021-1112
NVIDIA Linux kernel distributions contain a vulnerability in nvmap, where a null pointer dereference may lead to complete denial of service.
CVE-2021-1114
NVIDIA Linux kernel distributions contain a vulnerability in the kernel crypto node, where use after free may lead to complete denial of service.
Impact
- Denial of Service
- Privilege Escalation
- Information Disclosure
Affected Vendors
NVIDIA
Affected Products
- Jetson AGX Xavier series
- Jetson Xavier NX All 32.x versions prior to 32.6.1
- Jetson Xavier NX
- Jetson TX2 series
- Jetson TX2 NX
- Jetson Nano
- Jetson Nano 2GB
- Jetson TX1All 32.x versions prior to 32.6.1
- Jetson TX2 NXAll 32.x versions prior to 32.6.1
Remediation
For CVE-2021-1110
Update to latest version 32.6.1
For CVE-2021-1106
CVE-2021-1107
CVE-2021-1108
CVE-2021-1109
CVE-2021-1112
CVE-2021-1113
Update to latest version 32.6.1
For CVE-2021-1111
CVE-2021-1114
Update to latest version 32.6.1