Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6qjw-qgr8-m5c4

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Trusty contains a vulnerability in NVIDIA OTE protocol message parsing code, which is present in all the TAs. An incorrect bounds check leads to a memory leak of a portion of the heap situated after a stream buffer.

Trusty contains a vulnerability in NVIDIA OTE protocol message parsing code, which is present in all the TAs. An incorrect bounds check leads to a memory leak of a portion of the heap situated after a stream buffer.

EPSS

Процентиль: 16%
0.00051
Низкий

Дефекты

CWE-401

Связанные уязвимости

CVSS3: 5
nvd
больше 4 лет назад

Trusty contains a vulnerability in NVIDIA OTE protocol message parsing code, which is present in all the TAs. An incorrect bounds check can allow a local user through a malicious client to access memory from the heap in the TrustZone, which may lead to information disclosure.

EPSS

Процентиль: 16%
0.00051
Низкий

Дефекты

CWE-401