NVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker could cause the initialization of a resource with an insecure default. A successful exploit of this vulnerability might lead to information disclosure of encrypted data, data tampering, and partial denial of service across devices sharing the same machine ID.
References
| Link | Resource |
|---|---|
| https://nvd.nist.gov/vuln/detail/CVE-2026-24148 | Third Party Advisory US Government Resource |
| https://nvidia.custhelp.com/app/answers/detail/a_id/5797 | Vendor Advisory |
| https://www.cve.org/CVERecord?id=CVE-2026-24148 | Third Party Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
03 Apr 2026, 19:12
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Nvidia
Nvidia jetson Orin Nano 8gb Nvidia jetson Xavier Nx 8gb Nvidia jetson Linux Nvidia jetson Xavier Nx 16gb Nvidia jetson Orin Nx 8gb Nvidia jetson Agx Xavier Industrial Nvidia jetson Agx Xavier 64gb Nvidia jetson Agx Xavier 32gb Nvidia jetson Agx Orin Developer Kit Nvidia jetson Orin Nano Super Developer Kit Nvidia jetson Agx Orin Industrial Nvidia jetson Agx Orin 64gb Nvidia jetson Orin Nano 4gb Nvidia jetson Orin Nx 16gb Nvidia jetson Agx Orin 32gb |
|
| CPE | cpe:2.3:h:nvidia:jetson_agx_xavier_industrial:-:*:*:*:*:*:*:* cpe:2.3:h:nvidia:jetson_xavier_nx_16gb:-:*:*:*:*:*:*:* cpe:2.3:h:nvidia:jetson_agx_orin_32gb:-:*:*:*:*:*:*:* cpe:2.3:h:nvidia:jetson_orin_nano_8gb:-:*:*:*:*:*:*:* cpe:2.3:h:nvidia:jetson_agx_orin_industrial:-:*:*:*:*:*:*:* cpe:2.3:h:nvidia:jetson_agx_orin_64gb:-:*:*:*:*:*:*:* cpe:2.3:h:nvidia:jetson_agx_xavier_64gb:-:*:*:*:*:*:*:* cpe:2.3:h:nvidia:jetson_orin_nx_8gb:-:*:*:*:*:*:*:* cpe:2.3:h:nvidia:jetson_agx_xavier_32gb:-:*:*:*:*:*:*:* cpe:2.3:h:nvidia:jetson_xavier_nx_8gb:-:*:*:*:*:*:*:* cpe:2.3:h:nvidia:jetson_orin_nano_4gb:-:*:*:*:*:*:*:* cpe:2.3:h:nvidia:jetson_orin_nano_super_developer_kit:-:*:*:*:*:*:*:* cpe:2.3:o:nvidia:jetson_linux:*:*:*:*:*:*:*:* cpe:2.3:h:nvidia:jetson_orin_nx_16gb:-:*:*:*:*:*:*:* cpe:2.3:h:nvidia:jetson_agx_orin_developer_kit:-:*:*:*:*:*:*:* |
|
| References | () https://nvd.nist.gov/vuln/detail/CVE-2026-24148 - Third Party Advisory, US Government Resource | |
| References | () https://nvidia.custhelp.com/app/answers/detail/a_id/5797 - Vendor Advisory | |
| References | () https://www.cve.org/CVERecord?id=CVE-2026-24148 - Third Party Advisory |
31 Mar 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-31 17:16
Updated : 2026-04-03 19:12
NVD link : CVE-2026-24148
Mitre link : CVE-2026-24148
CVE.ORG link : CVE-2026-24148
JSON object : View
Products Affected
nvidia
- jetson_orin_nx_16gb
- jetson_xavier_nx_16gb
- jetson_agx_orin_32gb
- jetson_orin_nano_4gb
- jetson_linux
- jetson_orin_nano_super_developer_kit
- jetson_orin_nx_8gb
- jetson_orin_nano_8gb
- jetson_agx_xavier_32gb
- jetson_xavier_nx_8gb
- jetson_agx_xavier_industrial
- jetson_agx_orin_industrial
- jetson_agx_orin_developer_kit
- jetson_agx_xavier_64gb
- jetson_agx_orin_64gb
CWE
CWE-1188
Insecure Default Initialization of Resource
