CVE-2026-24153
MEDIUM EPSS 2.3%
Published Mar 31, 20263mo ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Published Mar 31, 2026 3mo ago
Last Modified Jun 17, 2026 1w ago
Description
NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled. A successful exploit of this vulnerability might lead to information disclosure.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity None
Availability None
Threat Intelligence
EPSS Exploit Probability
2.3% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-501
Affected Products 20
| Vendor | Product | Version | Range |
|---|---|---|---|
| nvidia | jetson_linux | * | <35.6.4 |
| nvidia | jetson_linux | * | ≥36.0 – <36.5 |
| nvidia | jetson_linux | 38.2 | any |
| nvidia | jetson_agx_orin_32gb | * | any |
| nvidia | jetson_agx_orin_64gb | * | any |
| nvidia | jetson_agx_orin_developer_kit | * | any |
| nvidia | jetson_agx_orin_industrial | * | any |
| nvidia | jetson_agx_thor_developer_kit | * | any |
| nvidia | jetson_agx_xavier_32gb | * | any |
| nvidia | jetson_agx_xavier_64gb | * | any |
| nvidia | jetson_agx_xavier_industrial | * | any |
| nvidia | jetson_orin_nano_4gb | * | any |
| nvidia | jetson_orin_nano_8gb | * | any |
| nvidia | jetson_orin_nano_super_developer_kit | * | any |
| nvidia | jetson_orin_nx_16gb | * | any |
| nvidia | jetson_orin_nx_8gb | * | any |
| nvidia | jetson_t4000 | * | any |
| nvidia | jetson_t5000 | * | any |
| nvidia | jetson_xavier_nx_16gb | * | any |
| nvidia | jetson_xavier_nx_8gb | * | any |
References 3
- nvd.nist.gov https://nvd.nist.gov/vuln/detail/CVE-2026-24153
- nvidia.custhelp.com https://nvidia.custhelp.com/app/answers/detail/a_id/5797
- cve.org https://www.cve.org/CVERecord?id=CVE-2026-24153
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.