CVE-2025-33182 Details
Description
NVIDIA Jetson Linux contains a vulnerability in UEFI, where improper authentication may allow a privileged user to cause corruption of the Linux Device Tree. A successful exploitation of this vulnerability might lead to data tampering, denial of service.
A vulnerability exists in NVIDIA Jetson Linux UEFI components, where improper authentication could enable a privileged user to corrupt the Linux Device Tree. Exploitation of this vulnerability may result in data tampering and denial-of-service conditions.
Users can upgrade to NVIDIA Jetson Linux versions 35.6.3 and newer, 36.4.4 and newer, or for IGX Orin, Kernel SRU 1035 and newer. Instructions for downloading this update are available on the NVIDIA Jetson Download Center and the IGX Downloads page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 14, 2025CISA-ADP
Assessed Oct 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://nvidia.custhelp.com/app/answers/detail/a_id/5716 | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| NVIDIA Jetson Orin | All versions |
CPE
Remediation
| |
| NVIDIA Jetson Xavier | All versions |
CPE
Remediation
| |
| NVIDIA Jetson Thor | All versions |
CPE
Remediation
| |
| NVIDIA IGX Orin | All versions |
CPE
Remediation
| |
| NVIDIA Jetson Linux | <= 35.6.2 (semver) <= 36.4.3 (semver) <= 38.2.1 (semver) |
CPE
Remediation
| |
| NVIDIA IGX OS | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 14, 2025 | New CVE Received | [email protected] |
Volerion