CVE-2026-24148 Details
Description
NVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker could cause the initialization of a resource with an insecure default. A successful exploit of this vulnerability might lead to information disclosure of encrypted data, data tampering, and partial denial of service across devices sharing the same machine ID.
A vulnerability exists in NVIDIA Jetson devices running JetPack, specifically in the system initialization logic. This flaw allows an unprivileged attacker to initialize a resource with an insecure default. Exploitation of this vulnerability could result in the unauthorized disclosure of encrypted data, unauthorized data modification, and a partial denial-of-service on devices sharing the same machine ID.
Users can update to Jetson Linux versions 35.6.4 or 36.5. For Jetson Thor, version 38.4 is available. The update can be downloaded from the APT server or the Jetson Download Center.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://nvd.nist.gov/vuln/detail/CVE-2026-24148 | [email protected] | Third Party AdvisoryUS Government Resource |
| https://nvidia.custhelp.com/app/answers/detail/a_id/5797 | [email protected] | Vendor Advisory |
| https://www.cve.org/CVERecord?id=CVE-2026-24148 | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1188 | Initialization of a Resource with an Insecure Default | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nvidia jetson linux | < 35.6.4 >= 36.0, < 36.5 |
CPE
Remediation
| |
| nvidia jetson agx orin 32gb | All versions |
CPE
Remediation
| |
| nvidia jetson agx orin 64gb | All versions |
CPE
Remediation
| |
| nvidia jetson agx orin developer kit | All versions |
CPE
Remediation
| |
| nvidia jetson agx orin industrial | All versions |
CPE
Remediation
| |
| nvidia jetson agx xavier 32gb | All versions |
CPE
Remediation
| |
| nvidia jetson agx xavier 64gb | All versions |
CPE
Remediation
| |
| nvidia jetson agx xavier industrial | All versions |
CPE
Remediation
| |
| nvidia jetson orin nano 4gb | All versions |
CPE
Remediation
| |
| nvidia jetson orin nano 8gb | All versions |
CPE
Remediation
| |
| nvidia jetson orin nano super developer kit | All versions |
CPE
Remediation
| |
| nvidia jetson orin nx 16gb | All versions |
CPE
Remediation
| |
| nvidia jetson orin nx 8gb | All versions |
CPE
Remediation
| |
| nvidia jetson xavier nx 16gb | All versions |
CPE
Remediation
| |
| nvidia jetson xavier nx 8gb | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 3, 2026 | Initial Analysis | [email protected] |
| Mar 31, 2026 | New CVE Received | [email protected] |