NVIDIA Jetson Linux has vulnerability in initrd, where an unprivileged attacker with physical access coul inject incorrect command line arguments. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, data tampering, and information disclosure.
History

Wed, 01 Apr 2026 02:15:00 +0000

Type Values Removed Values Added
Title Physical Access Exploit Allows Unauthorized Command Injection in NVIDIA Jetson Initrd
First Time appeared Nvidia
Nvidia jetson Orin Series
Nvidia jetson Thor
Nvidia jetson Xavier Series
Vendors & Products Nvidia
Nvidia jetson Orin Series
Nvidia jetson Thor
Nvidia jetson Xavier Series

Tue, 31 Mar 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 31 Mar 2026 16:45:00 +0000

Type Values Removed Values Added
Description NVIDIA Jetson Linux has vulnerability in initrd, where an unprivileged attacker with physical access coul inject incorrect command line arguments. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, data tampering, and information disclosure.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published: 2026-03-31T16:23:34.752Z

Updated: 2026-03-31T17:46:32.434Z

Reserved: 2026-01-21T19:09:29.850Z

Link: CVE-2026-24154

cve-icon Vulnrichment

Updated: 2026-03-31T17:46:27.806Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-31T17:16:30.680

Modified: 2026-04-01T14:24:02.583

Link: CVE-2026-24154

cve-icon Redhat

No data.