CVE-2025-23269 Details
Description
NVIDIA Jetson Linux contains a vulnerability in the kernel where an attacker may cause an exposure of sensitive information due to a shared microarchitectural predictor state that influences transient execution. A successful exploit of this vulnerability may lead to information disclosure.
A vulnerability exists in the NVIDIA Jetson Linux kernel, where an attacker can exploit a shared microarchitectural predictor state that affects transient execution, leading to the exposure of sensitive information. This vulnerability is present in NVIDIA Jetson Orin, IGX Orin, and Xavier devices, in all versions prior to JP5.x: 35.6.2 and all versions prior to JP6.x: 36.4.4 for Jetson Orin, and all versions prior to JP5.x: 35.6.2 for Xavier. For IGX Orin, all versions prior to IGX 1.1.2 are affected.
Users can upgrade to NVIDIA Jetson Linux versions 35.6.2 or 36.4.4, depending on their current version. For IGX Orin, users should upgrade to IGX 1.1.2.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 17, 2025CISA-ADP
Assessed Jul 17, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://nvidia.custhelp.com/app/answers/detail/a_id/5662 | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| NVIDIA Jetson Orin | < JP5.x: 35.6.2 < JP6.x: 36.4.4 |
CPE
Remediation
| |
| NVIDIA Xavier | All versions |
CPE
Remediation
| |
| NVIDIA IGX Orin | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 17, 2025 | New CVE Received | [email protected] |
Volerion