NVIDIA Tegra kernel driver contains a vulnerability in NVIDIA NVDEC, where a user with high privileges might be able to read from or write to a memory location that is outside the intended boundary of the buffer, which may lead to denial of service, Information disclosure, loss of Integrity, or possible escalation of privileges. References: https://nvidia.custhelp.com/app/answers/detail/a_id/5259
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 2044519]
This is in their driver code that is not upstream yet.
Hosted OpenShift/Managed Services notaffected.
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-34402