NVIDIA Jetson initrd flaw lets attackers with physical access bypass Secure Boot
jedisct1 · x · 2026-09-04
ONEKEY Research Lab disclosed a command injection vulnerability in NVIDIA Jetson Linux's initrd: an unprivileged attacker with physical access can inject arbitrary commands during boot to bypass Secure Boot.
- Affected: Jetson Xavier, Orin and Thor series; Jetson For Linux versions 35.6.4, 36.5.0, 38.2.0/38.2.1, 38.4.0 and 39.2.0
- Fixed in: 35.6.5, 36.5.2 and 39.2.1
- Severity: CVSS 4.0 score of 7.0 (High), compromising confidentiality, integrity and availability
- Jetson powers security-sensitive edge devices like robots, drones, industrial machines and smart cameras; researchers urge patching and fusing signing keys
CVE IDs will be assigned when NVIDIA publishes its advisory.
More from Infra
- Inference startup insider: "we just resell NVIDIA GPUs" — VCs question the moat — firstadopter · 2026-09-04
- Leak claims GPT-6 Astra trained on 100,000+ GPUs at OpenAI's Stargate site — BLUECOW009 · 2026-09-04
- Users dispute credit burn; provider says KV cache was always on, scaling across providers — arthurcolle · 2026-09-04
- Modal adds support for running Cursor Cloud Agents in custom sandboxes — AAAzzam · 2026-09-04
- One cluster alone could train 68 GPT-6-scale models by 2029, and FP4 could double that — scaling01 · 2026-09-04
- Ollama's new interactive menu makes launching local models and agents easier — Technovangelist · 2026-09-04