Description
NVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker could cause the initialization of a resource with an insecure default. A successful exploit of this vulnerability might lead to information disclosure of encrypted data, data tampering, and partial denial of service across devices sharing the same machine ID.
Problem types
CWE-1188 Initialization of a Resource with an Insecure Default
Product status
All versions prior to 35.6.4
All versions prior to 36.5
References
nvd.nist.gov/vuln/detail/CVE-2026-24148
www.cve.org/CVERecord?id=CVE-2026-24148
nvidia.custhelp.com/app/answers/detail/a_id/5797