CVE-2026-24153
Received Received - Intake
Information Disclosure via Enabled nvluks in NVIDIA Jetson Linux Initrd

Publication date: 2026-03-31

Last updated on: 2026-04-03

Assigner: NVIDIA Corporation

Description
NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled. A successful exploit of this vulnerability might lead to information disclosure.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-03-31
Last Modified
2026-04-03
Generated
2026-05-07
AI Q&A
2026-03-31
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
nvidia jetson_linux to 35.6.4 (exc)
nvidia jetson_linux From 36.0 (inc) to 36.5 (exc)
nvidia jetson_linux 38.2
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-501 The product mixes trusted and untrusted data in the same data structure or structured message.
Attack-Flow Graph
AI Powered Q&A
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

CVE-2026-24153 involves a vulnerability that may lead to information disclosure due to improper handling of the nvluks trusted application in NVIDIA Jetson Linux. Since the vulnerability can result in unauthorized disclosure of sensitive information, it could potentially impact compliance with data protection standards and regulations such as GDPR and HIPAA, which require safeguarding confidential data against unauthorized access.

However, the provided information does not explicitly mention any direct effects or assessments regarding compliance with specific standards or regulations.


Can you explain this vulnerability to me?

CVE-2026-24153 is a vulnerability in NVIDIA Jetson Linux affecting the initrd (initial RAM disk) environment. The issue arises because the nvluks trusted application is not disabled by default. This flaw allows an attacker with physical access and low privileges to potentially cause information disclosure.


How can this vulnerability impact me? :

The vulnerability can lead to unauthorized disclosure of sensitive information. An attacker with physical access and low privileges could exploit this flaw to gain access to confidential data. The impact is limited to confidentiality, with no effect on integrity or availability.


What immediate steps should I take to mitigate this vulnerability?

To mitigate CVE-2026-24153, users should install the security update provided by NVIDIA. This update is available via the APT server or the Jetson Download Center.

The vulnerability is fixed in Jetson Linux versions 35.6.4, 36.5, 38.2, and 38.4 for Jetson Xavier Series, Jetson Orin Series, and Jetson Thor platforms. Upgrading to one of these versions or later will address the issue.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart