Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Nvidia Patches High-Severity Vulnerabilities in AI, Networking Products

Nvidia has patched high-severity vulnerabilities in its Jetson, Mellanox OS, OnyX, Skyway, and MetroX products.

Nvidia patches

Nvidia this week announced patches for vulnerabilities affecting several of its artificial intelligence and networking products.

The chip giant has published two security bulletins. One of them covers CVE-2024-0108, a high-severity flaw affecting Jetson products, which are designed for robotics and embedded edge AI applications. 

The security hole impacts Jetson AGX Xavier, Jetson Xavier NX, Jetson TX2, Jetson TX2 NX, Jetson TX1, and Jetson Nano on Jetson Linux. 

“Nvidia Jetson Linux contains a vulnerability in NvGPU where error handling paths in GPU MMU mapping code fail to clean up a failed mapping attempt. A successful exploit of this vulnerability may lead to denial of service, code execution, and escalation of privileges,” the company explained in its advisory.

The second security bulletin covers vulnerabilities affecting the Mellanox OS switch operating system for data centers and its successor OnyX, the Skyway InfiniBand-to-Ethernet gateway, and the MetroX long-haul system.

One vulnerability, CVE-2024-0101, is a high-severity ‘ipfilter’ issue that can be exploited to launch denial-of-service (DoS) attacks against switches. 

Advertisement. Scroll to continue reading.

The second flaw, CVE-2024-0104, is a medium-severity issue that can result in improper access.

“A successful exploit of this vulnerability might lead to information disclosure, data tampering, and escalation of privileges,” Nvidia said.

Since the beginning of the year, the company has informed customers about more than 60 vulnerabilities found in its products

Related: Nvidia Patches High-Severity GPU Driver Vulnerabilities

Related: Code Execution Flaws Haunt Nvidia ChatRTX for Windows

Related: Credentials of 71,000 Nvidia Employees Leaked Following Cyberattack

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

With "Shadow AI" usage becoming prevalent in organizations, learn how to balance the need for rapid experimentation with the rigorous controls required for enterprise-grade deployment.

Register

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

People on the Move

Chris Sistrunk has been promoted to Practice Leader for Mandiant's OT Security Consulting.

Nudge Security has appointed Patrick Dillon as its Chief Revenue Officer.

AutoNation has appointed Brian Fricke as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.