### [CVE-2022-28196](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28196) ![](https://img.shields.io/static/v1?label=Product&message=Jetson%20AGX%20Xavier%20series%2C%20Jetson%20Xavier%20NX%2C%20Jetson%20TX2%20NX%2C%20Jetson%20TX2%20series&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-20%20Improper%20Input%20Validation&color=brighgreen) ### Description NVIDIA Jetson Linux Driver Package contains a vulnerability in the Cboot blob_decompress function, where insufficient validation of untrusted data may allow a local attacker with elevated privileges to cause a memory buffer overflow, which may lead to code execution, limited loss of Integrity, and limited denial of service. The scope of impact can extend to other components. ### POC #### Reference - https://nvidia.custhelp.com/app/answers/detail/a_id/5343 #### Github No PoCs found on GitHub currently.