CVE-2021-34401 is a high-severity vulnerability (CVSS 7.8) affecting NVIDIA Linux kernel distributions, specifically within the nvmap NVGPU_IOCTL_CHANNEL_SET_ERROR_NOTIFIER. This improper access control flaw can lead to code execution, data integrity compromise, or denial of service on affected Google Android and NVIDIA Shield Experience devices. The attack vector is local, with low attack complexity and no user interaction required, allowing an authenticated local attacker to achieve significant impact. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.0CPE matchmatch criteria | cpe:2.3:a:nvidia:shield_experience:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.