CVE-2017-0866: NVIDIA Tegra x1 Firmware

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

An elevation of privilege vulnerability in the Direct rendering infrastructure of the NVIDIA Tegra X1 where an unchecked input from userspace is passed as a pointer to kfree. This could lead to kernel memory corruption and possible code execution. This issue is rated as moderate. Product: Pixel. Version: N/A. Android ID: A-38415808. References: N-CVE-2017-0866.

Affected products

  • NVIDIA Tegra x1 Firmware: affected versions not specified

Published 2017-11-16. Last modified 2026-06-17.