CVE-2026-24153Medium· 5.2▾ SunlitNVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled. A successful exploit of this vulnerability might lead to information disclosure.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 28.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 24.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled. A successful exploit of this vulnerability might lead to information disclosure.
jetson_linux < 35.6.4jetson_linux >= 36.0, < 36.5jetson_linux = 38.2Upgrade past the affected range:
jetson_linux 36.5Connected by shared product, vendor, weakness, or advisory.
CVE-2026-24154High· 7.6NVIDIA Jetson Linux has vulnerability in initrd, where an unprivileged attacker with physical access coul inject incorrect command line arguments
CVE-2026-24148High· 8.3NVIDIA Jetson for JetPack contains a vulnerability in the system initialization logic, where an unprivileged attacker could cause the initialization of a resource with an insecure default
CVE-2026-24239High· 7.8NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious data created by an attacker could cause remote code execution
CVE-2026-65111High· 7.8NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious input created by an attacker could cause a code injection
CVE-2026-24267High· 7.8NVIDIA NeMo Speech for all platforms contains a vulnerability in the speech data explorer component, where malicious data created by an attacker could cause remote code execution
CVE-2026-65179High· 8.8NVIDIA NeMo contains a vulnerability in the TabularTokenizer class where it deserializes an untrusted, attacker-controlled .pkl file via pickle.load() without validation