Executive brief
NVIDIA Jetson Linux, the operating system used in Jetson Xavier, Orin, and Thor hardware modules, contains a security flaw in its initial boot process. An attacker with physical access to the device can manipulate startup commands to gain full control over the system. This could lead to the theft of sensitive data, permanent tampering with the device's software, or a complete shutdown of operations.
Technical details
A command injection vulnerability (CWE-78) exists in the initial RAM disk (initrd) of NVIDIA Jetson Linux. An unprivileged attacker with physical access to the hardware can inject malicious command-line arguments during the boot sequence. This bypasses standard security controls, potentially leading to arbitrary code execution, privilege escalation to root, and full system compromise. The vulnerability affects Jetson Xavier, Orin, and Thor series modules. NVIDIA has released patches in Jetson Linux versions 35.6.4 and 36.5 to address this issue.
Affected products
- NVIDIA Jetson Linux (35.x) All versions prior to 35.6.4
- NVIDIA Jetson Linux (36.x) All versions prior to 36.5
- NVIDIA Jetson Linux (38.x) 38.2
Timeline
- 2026-03-31: disclosed
- 2026-03-31: advisory