Executive brief
NVIDIA Jetson Linux, an operating system used in embedded AI and robotics platforms, contains a security flaw where a specific trusted application is not properly disabled during the boot process. If exploited, this could allow an unauthorized person with local or physical access to the device to view sensitive information. This could lead to the exposure of proprietary data or system credentials.
Technical details
A vulnerability exists in the NVIDIA Jetson Linux initrd (initial RAM disk) component due to a trust boundary violation. Specifically, the 'nvluks' trusted application is not disabled as intended, which can be leveraged by a local attacker with low privileges or an attacker with physical access. Successful exploitation allows for unauthorized information disclosure from the secure environment. The issue affects various Jetson series including Xavier, Orin, and Thor. Patches are available in versions 35.6.4 and 36.5.
Affected products
- NVIDIA Jetson Linux (35) prior to 35.6.4
- NVIDIA Jetson Linux (36) prior to 36.5
- NVIDIA Jetson Linux (38) 38.2
Timeline
- 2026-03-31: disclosed
- 2026-03-31: advisory