CVE-2026-24148 is a critical vulnerability affecting NVIDIA Jetson for JetPack, where an unprivileged attacker can exploit insecure system initialization logic. Rated 9.4 CVSS, this remotely exploitable flaw requires no user interaction or privileges, potentially leading to high-impact information disclosure of encrypted data, data tampering, and partial denial of service. While no public exploit code is currently available on platforms like Metasploit, this vulnerability is listed on the Hot List, indicating active exploitation and some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 35.6.4CPE matchmatch criteria | cpe:2.3:o:nvidia:jetson_linux:*:*:*:*:*:*:*:* | ||
>= 36.0, < 36.5CPE matchmatch criteria | cpe:2.3:o:nvidia:jetson_linux:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.