CVE-2026-24153
Information Disclosure via Enabled nvluks in NVIDIA Jetson Linux Initrd
Publication date: 2026-03-31
Last updated on: 2026-04-03
Assigner: NVIDIA Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| nvidia | jetson_linux | to 35.6.4 (exc) |
| nvidia | jetson_linux | From 36.0 (inc) to 36.5 (exc) |
| nvidia | jetson_linux | 38.2 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-501 | The product mixes trusted and untrusted data in the same data structure or structured message. |
Attack-Flow Graph
AI Powered Q&A
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
CVE-2026-24153 involves a vulnerability that may lead to information disclosure due to improper handling of the nvluks trusted application in NVIDIA Jetson Linux. Since the vulnerability can result in unauthorized disclosure of sensitive information, it could potentially impact compliance with data protection standards and regulations such as GDPR and HIPAA, which require safeguarding confidential data against unauthorized access.
However, the provided information does not explicitly mention any direct effects or assessments regarding compliance with specific standards or regulations.
Can you explain this vulnerability to me?
CVE-2026-24153 is a vulnerability in NVIDIA Jetson Linux affecting the initrd (initial RAM disk) environment. The issue arises because the nvluks trusted application is not disabled by default. This flaw allows an attacker with physical access and low privileges to potentially cause information disclosure.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized disclosure of sensitive information. An attacker with physical access and low privileges could exploit this flaw to gain access to confidential data. The impact is limited to confidentiality, with no effect on integrity or availability.
What immediate steps should I take to mitigate this vulnerability?
To mitigate CVE-2026-24153, users should install the security update provided by NVIDIA. This update is available via the APT server or the Jetson Download Center.
The vulnerability is fixed in Jetson Linux versions 35.6.4, 36.5, 38.2, and 38.4 for Jetson Xavier Series, Jetson Orin Series, and Jetson Thor platforms. Upgrading to one of these versions or later will address the issue.