CVE-2026-24148: NVIDIA Jetson Linux

Critical severity, CVSS 9.4. EPSS: 0.3% chance of exploitation in the next 30 days.

NVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker could cause the initialization of a resource with an insecure default. A successful exploit of this vulnerability might lead to information disclosure of encrypted data, data tampering, and partial denial of service across devices sharing the same machine ID.

Affected products

  • NVIDIA Jetson Linux: before 35.6.4 (fixed in 35.6.4); from 36.0, before 36.5 (fixed in 36.5)

Published 2026-03-31. Last modified 2026-07-24.