CVE-2026-24153Disclosure(nvidia / jetson_agx_orin_32gb)

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled. A successful exploit of this vulnerability might lead to information disclosure.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-501

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jetson_agx_orin_32gb
  • jetson_agx_orin_64gb
  • jetson_agx_orin_developer_kit
  • jetson_agx_orin_industrial

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • False Positive: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-04-14); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
jetson_agx_orin_32gbjetson_agx_orin_64gbjetson_agx_orin_developer_kitjetson_agx_orin_industrialjetson_agx_thor_developer_kitjetson_agx_xavier_32gbjetson_agx_xavier_64gbjetson_agx_xavier_industrialjetson_linuxjetson_orin_nano_4gb

2 versions affected across 18 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-04-14: 1Mentions · 2026-04-19: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-19: 104-1404-19
Signal classification2 categories
Disclosure
150.0%
False Positive
150.0%
Referenced assets3 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-141
Disclosure1
2026-04-191
False Positive1
Full discourse2 posts
  • Amichai Yifrach@The_H1tchH1ker
    False Positive

    Misled Trust at Scale: Jetson Orin CVEs If you’re using @nvidia Jetson Orin, this may already be in your product. My research led to CVE-2026-24154 & CVE-2026-24153 They look like typical vulns. They’re not. They expose a deeper issue: systems that verify correctly, but carry development trust assumptions into production. Result: → Root shell during early boot → Observe live decryption → Extract keys & mount rootfs (no crypto broken) Nothing is broken. Trust just happens at the wrong moment. And Orin is everywhere: AI, robotics, industrial, edge. This is not a CVE story. It’s a production trust failure. Full breakdown 👇 https://lnkd.in/dcKj3ktd

    Post summary

    The author claims CVE‑2026‑24154 and CVE‑2026‑24153 on Jetson Orin are not genuine vulnerabilities but rather a production trust failure that could lead to early‑boot root access. No PoC, exploit code, or patch information is shared, and no active exploitation is reported.

    14072860
    441 followersView on X
  • Amichai Yifrach@The_H1tchH1ker
    Disclosure

    Production AI Devices Are More Exposed Than You Think Recently, NVIDIA assigned two CVEs to vulnerabilities I discovered in the Jetson platform: • CVE-2026-24154 = initrd command line fault injection → potential code execution, privilege escalation, full impact (CIA) • CVE-2026-24153 = nvluks trusted application not disabled → information disclosure (crypto exposure path) Both are now publicly acknowledged by NVIDIA (credited to th3_h1tchh1ker - that's me :) ). - https://lnkd.in/d3BA3EEb But the real story is not the CVEs. Jetson Orin is not just a development kit. It is embedded in thousands of production systems across robotics, medical devices, industrial control, and edge AI. And that’s where this becomes interesting. During my research on Jetson Orin NX, I demonstrated that: • Manipulation of initrd kernel parameters under physical access conditions can be abused to alter early boot behavior, potentially leading to code execution and privilege escalation • The root filesystem decryption flow can be observed and interacted with when early boot is compromised, exposing sensitive material • Secure Boot assumptions break down when early-stage execution paths are not strictly enforced This is not a remote exploit story. This is a real-world deployment story. In practice, with realistic physical access scenarios such as supply chain handling, field installation, or maintenance, an attacker can: • Interfere with the system before the OS is fully initialized • Access sensitive data through exposed initialization flows • Establish control paths below traditional OS-level defenses NVIDIA also updated their documentation following additional findings related to UART exposure and UEFI access paths. What this highlights is a broader industry pattern: 👉 Systems designed for developer flexibility are often deployed without being fully transitioned into production-secure configurations At scale, this creates a systemic risk. Not because of a single vulnerability, but because of how trust is assumed rather than enforced in early system states. Appreciate NVIDIA PSIRT for the professional handling and coordinated disclosure. It also reinforces a fundamental point: If compromise is possible below the OS, then anything above the OS is operating on borrowed trust. More to come on this research. Including a fascinating webinar around secure boot and its weaknesses, on http://Trainsec.net - stay tuned and follow. Th3_H1tchH1ker #NVIDIA #Jetson #CYMDALL #cybersecurity #infosec #security #embedded #iot #ai #tech

    Post summary

    The author announces two NVIDIA Jetson CVEs with technical details about initrd-based code execution and information disclosure but does not provide a PoC, exploit code, or active exploitation evidence. The post focuses on disclosure and highlights potential risks in production deployments.

    02041406
    434 followersView on X
CPE platform detail19 entries

19 of 19 entries

PartVendorProductVersionTarget SWTarget HW
HWnvidiajetson_agx_orin_32gb---
HWnvidiajetson_agx_orin_64gb---
HWnvidiajetson_agx_orin_developer_kit---
HWnvidiajetson_agx_orin_industrial---
HWnvidiajetson_agx_thor_developer_kit---
HWnvidiajetson_agx_xavier_32gb---
HWnvidiajetson_agx_xavier_64gb---
HWnvidiajetson_agx_xavier_industrial---
OSnvidiajetson_linux---
OSnvidiajetson_linux38.2--
HWnvidiajetson_orin_nano_4gb---
HWnvidiajetson_orin_nano_8gb---
HWnvidiajetson_orin_nano_super_developer_kit---
HWnvidiajetson_orin_nx_16gb---
HWnvidiajetson_orin_nx_8gb---
HWnvidiajetson_t4000---
HWnvidiajetson_t5000---
HWnvidiajetson_xavier_nx_16gb---
HWnvidiajetson_xavier_nx_8gb---

Explore more