7.6

CVE-2026-24154

NVIDIA Jetson Linux has vulnerability in initrd, where an unprivileged attacker with physical access coul inject incorrect command line arguments. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, data tampering, and information disclosure.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NvidiaJetson Linux Version < 35.6.4
   NvidiaJetson Agx Orin 32gb Version-
   NvidiaJetson Agx Orin 64gb Version-
   NvidiaJetson Agx Orin Developer Kit Version-
   NvidiaJetson Agx Orin Industrial Version-
   NvidiaJetson Agx Thor Developer Kit Version-
   NvidiaJetson Agx Xavier 32gb Version-
   NvidiaJetson Agx Xavier 64gb Version-
   NvidiaJetson Agx Xavier Industrial Version-
   NvidiaJetson Orin Nano 4gb Version-
   NvidiaJetson Orin Nano 8gb Version-
   NvidiaJetson Orin Nano Super Developer Kit Version-
   NvidiaJetson Orin Nx 16gb Version-
   NvidiaJetson Orin Nx 8gb Version-
   NvidiaJetson T4000 Version-
   NvidiaJetson T5000 Version-
   NvidiaJetson Xavier Nx 16gb Version-
   NvidiaJetson Xavier Nx 8gb Version-
NvidiaJetson Linux Version >= 36.0 < 36.5
   NvidiaJetson Agx Orin 32gb Version-
   NvidiaJetson Agx Orin 64gb Version-
   NvidiaJetson Agx Orin Developer Kit Version-
   NvidiaJetson Agx Orin Industrial Version-
   NvidiaJetson Agx Thor Developer Kit Version-
   NvidiaJetson Agx Xavier 32gb Version-
   NvidiaJetson Agx Xavier 64gb Version-
   NvidiaJetson Agx Xavier Industrial Version-
   NvidiaJetson Orin Nano 4gb Version-
   NvidiaJetson Orin Nano 8gb Version-
   NvidiaJetson Orin Nano Super Developer Kit Version-
   NvidiaJetson Orin Nx 16gb Version-
   NvidiaJetson Orin Nx 8gb Version-
   NvidiaJetson T4000 Version-
   NvidiaJetson T5000 Version-
   NvidiaJetson Xavier Nx 16gb Version-
   NvidiaJetson Xavier Nx 8gb Version-
NvidiaJetson Linux Version38.2
   NvidiaJetson Agx Orin 32gb Version-
   NvidiaJetson Agx Orin 64gb Version-
   NvidiaJetson Agx Orin Developer Kit Version-
   NvidiaJetson Agx Orin Industrial Version-
   NvidiaJetson Agx Thor Developer Kit Version-
   NvidiaJetson Agx Xavier 32gb Version-
   NvidiaJetson Agx Xavier 64gb Version-
   NvidiaJetson Agx Xavier Industrial Version-
   NvidiaJetson Orin Nano 4gb Version-
   NvidiaJetson Orin Nano 8gb Version-
   NvidiaJetson Orin Nano Super Developer Kit Version-
   NvidiaJetson Orin Nx 16gb Version-
   NvidiaJetson Orin Nx 8gb Version-
   NvidiaJetson T4000 Version-
   NvidiaJetson T5000 Version-
   NvidiaJetson Xavier Nx 16gb Version-
   NvidiaJetson Xavier Nx 8gb Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.102
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 0.9 5.9
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
psirt@nvidia.com 7.6 0.9 6
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.