← Vulnerability feed

Vulnerability record · CVE-2022-28194 · published 27 April 2022

CVE-2022-28194: Nvidia jetson linux memory buffer overflow vulnerability

Nvidia · Jetson Linux

NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where, if TFTP is enabled, a local attacker with elevated privileges can cause a memory buffer overflow, which may lead to code execution, loss of Integrity, limited denial of service, and some impact to confidentiality.

5.6 CVSS 3.1 Medium EPSS 0.32% · top 77.6% CWE-119 · Memory buffer overflow
5.6CVSS 3.1 base score, v2 4.4
0.32%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot module tegrabl_cbo.c, where, if TFTP is enabled, a local attacker with elevated privileges can cause a memory buffer overflow, which may lead to code execution, loss of Integrity, limited denial of service, and some impact to confidentiality.

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:L

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-28194 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.4CVE-2026-24148Nvidia jetson linux insecure default initialization vulnerabilityNVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker could cause the initialization …EPSS 0.35%8.8CVE-2024-0108Nvidia jetson linux vulnerabilityNVIDIA Jetson Linux contains a vulnerability in NvGPU where error handling paths in GPU MMU mapping code fail to clean up a failed mapping attempt. A…EPSS 0.23%7.9CVE-2022-42269Nvidia jetson linux improper input validation vulnerabilityNVIDIA Trusted OS contains a vulnerability in an SMC call handler, where failure to validate untrusted input may allow a highly privileged local atta…EPSS 0.18%7.8CVE-2022-42270Nvidia jetson linux stack-based buffer overflow vulnerabilityNVIDIA distributions of Linux contain a vulnerability in nvdla_emu_task_submit, where unvalidated input may allow a local attacker to cause stack-bas…EPSS 0.18%7.8CVE-2021-1107Nvidia jetson linux vulnerabilityNVIDIA Linux kernel distributions contain a vulnerability in nvmap NVMAP_IOC_WRITE* paths, where improper access controls may lead to code execution,…EPSS 0.28%7.8CVE-2021-1106Nvidia jetson linux out-of-bounds write vulnerabilityNVIDIA Linux kernel distributions contain a vulnerability in nvmap, where writes may be allowed to read-only buffers, which may result in escalation …EPSS 0.26%7.8CVE-2021-34380Nvidia jetson linux out-of-bounds write vulnerabilityBootloader contains a vulnerability in NVIDIA MB2 where potential heap overflow might cause corruption of the heap metadata, which might lead to arbi…EPSS 0.25%7.8CVE-2021-34381Nvidia jetson linux integer overflow vulnerabilityTrusty TLK contains a vulnerability in the NVIDIA TLK kernel function where a lack of checks allows the exploitation of an integer overflow on the si…EPSS 0.21%

Source: NIST National Vulnerability Database (record CVE-2022-28194), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.