Vulnerability record · CVE-2022-28196 · published 27 April 2022
CVE-2022-28196: Nvidia jetson linux improper input validation vulnerability
Nvidia · Jetson Linux
NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot blob_decompress function, where insufficient validation of untrusted data may allow a local attacker with elevated privileges to cause a memory buffer overflow, which may lead to code execution, limited loss of Integrity, and limited denial of service. The scope of impact can extend to other components.
Description
NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot blob_decompress function, where insufficient validation of untrusted data may allow a local attacker with elevated privileges to cause a memory buffer overflow, which may lead to code execution, limited loss of Integrity, and limited denial of service. The scope of impact can extend to other components.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:L
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://nvidia.custhelp.com/app/answers/detail/a_id/5343 | Vendor Advisory |
| https://nvidia.custhelp.com/app/answers/detail/a_id/5343 | Vendor Advisory |
Track CVE-2022-28196 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-28196), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.