CVE-2026-24154
7.6NVIDIA · Jetson Linux
NVIDIA Jetson Linux contains an OS command injection vulnerability in initrd that allows an attacker with physical access to execute arbitrary code or escalate privileges.
Executive summary
An unprivileged attacker with physical access can exploit an OS command injection flaw in NVIDIA Jetson Linux to achieve full system compromise.
Vulnerability
This vulnerability involves improper neutralization of special elements in the initrd component, which allows an unprivileged attacker with physical access to inject malicious command line arguments. The flaw is classified as an OS command injection (CWE-78) and can be triggered without prior authentication.
Business impact
The vulnerability carries a CVSS score of 7.6, reflecting the high potential for total system compromise despite the requirement for physical access. Successful exploitation may result in unauthorized code execution, privilege escalation, denial of service, data tampering, and the disclosure of sensitive information, posing a significant risk to operational integrity and data security.
Remediation
Immediate Action: Update affected NVIDIA Jetson devices to the recommended versions specified in the vendor security advisory (a_id/5797) immediately.
Proactive Monitoring: Monitor system logs for unusual boot sequences or unexpected modifications to command line arguments that may indicate an attempt to bypass security controls.
Compensating Controls: Restrict physical access to the hardware components of the Jetson devices to prevent unauthorized interaction with the boot process.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for complete system compromise and the impact on device integrity, administrators must prioritize the application of security patches provided by NVIDIA. Restricting physical access to sensitive hardware is a necessary secondary measure to mitigate the risk posed by this vulnerability until all systems are fully updated.