JetPack Jetson init flaw: unprivileged attacker could expose data
CVE-2026-24148 Published on March 31, 2026
NVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker could cause the initialization of a resource with an insecure default. A successful exploit of this vulnerability might lead to information disclosure of encrypted data, data tampering, and partial denial of service across devices sharing the same machine ID.
Vulnerability Analysis
CVE-2026-24148 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and a small impact on availability.
Weakness Type
Insecure Default Initialization of Resource
The software initializes or sets a resource with a default that is intended to be changed by the administrator, but the default is not secure.
Products Associated with CVE-2026-24148
Want to know whenever a new CVE is published for NVIDIA Jetson? stack.watch will email you.
Affected Versions
NVIDIA Jetson Xavier Series and Jetson Orin Series:- Version All versions prior to 35.6.4 is affected.
- Version All versions prior to 36.5 is affected.