# CVE-2026-24153

## Summary

- **CVE ID:** CVE-2026-24153
- **Severity:** MEDIUM
- **CVSS Score:** 5.2 (CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N)
- **CWE:** CWE-501
- **Published:** Mar 31, 2026
- **Last Modified:** Apr 1, 2026

## Description

NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled. A successful exploit of this vulnerability might lead to information disclosure.

## Affected Products

- NVIDIA — Jetson Xavier Series, Jetson Orin Series and Jetson Thor (All versions prior to 35.6.4)
- NVIDIA — Jetson Xavier Series, Jetson Orin Series and Jetson Thor (All versions prior to 36.5)
- NVIDIA — Jetson Xavier Series, Jetson Orin Series and Jetson Thor (38.2)

## References

- [CNA](https://nvidia.custhelp.com/app/answers/detail/a_id/5797)
- [CNA](https://nvd.nist.gov/vuln/detail/CVE-2026-24153)
- [CNA](https://www.cve.org/CVERecord?id=CVE-2026-24153)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.12%
- **EPSS Percentile:** 2.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._