Input validation error in NVIDIA Jetson TX1 L4T - CVE-2019-5680
Published: July 22, 2019 / Updated: July 22, 2019
NVIDIA Jetson TX1 L4T
Detailed vulnerability description
The vulnerability allows a local attacker to escalate privileges on the targeted system.
The vulnerability exists due to insufficient validation of user-supplied input when loading the "nvtboot-cpu" image in "nvtboot" in the Tegra bootloader. A local authenticated attacker can create a specially crafted application and escalate privileges on the target system.