Junglewise Threat Intelligence

CVE-2026-24148: NVIDIA Jetson insecure default initialization in system logic

CVE-2026-24148 · Severity: high · CVSS 8.3 · Published 2026-03-31

Technologies: Nvidia Jetson Linux. Vendors: Nvidia.

Executive brief

NVIDIA Jetson devices, which are used for AI and edge computing applications, contain a security flaw in how they start up and initialize system resources. An attacker with low-level access could exploit this to view encrypted sensitive information, modify system data, or cause service disruptions. This issue is particularly impactful for organizations deploying multiple devices that share the same machine identification settings.

Technical details

A vulnerability exists in the system initialization logic of NVIDIA Jetson Linux (JetPack) due to the use of insecure default resource initialization (CWE-1188). An unprivileged attacker with network access can exploit this flaw to compromise the confidentiality and integrity of the system. The impact includes the potential disclosure of encrypted data and data tampering. Notably, the vulnerability can lead to a partial denial of service across multiple devices if they share the same machine ID. Patches are available in Jetson Linux versions 35.6.4 and 36.5.

Affected products

  • NVIDIA Jetson Xavier Series and Jetson Orin Series (Jetson Linux) Prior to 35.6.4, 36.0 prior to 36.5

Timeline

  • 2026-03-31: disclosed
  • 2026-03-31: advisory

References

Related threats