NVIDIA Jetson Linux (UEFI): UEFI accepts a Linux Device Tree without checking authorization, so anyone who reaches
Impact
UEFI accepts a Linux Device Tree without checking authorization, so anyone who reaches a privileged account on the device can rewrite the hardware description the kernel boots against. That is persistence below the operating system: the tampered DTB survives an OS reinstall, and a reimaged device comes back still owned. For a fleet of edge or embedded GPU devices this is the case where your standard recovery play - wipe and redeploy - does not actually clear the attacker.
Who can reach it
Requires an already-privileged account, but NVIDIA scores it as network-reachable, meaning the vulnerable update path is exposed to the device's privileged management surface rather than needing hands on the hardware. Realistically it is a second-stage move: chain any root-level bug into it and you convert a temporary foothold into firmware-level persistence.
What to do
Update Jetson Linux to 35.6.3 or later on Xavier and Orin. Separately, any device you suspect was reached at root needs a full firmware reflash and DTB verification, not an OS update - an in-place upgrade will not remove an already-planted Device Tree. Restrict who can reach the privileged management interface on these devices in the meantime.
References
Related entries
- NVIDIA NeMo Agent Toolkit (Web UI): The chat API endpoint is vulnerable to server-side request forgery, so an attackerCVE-2025-33203 · NVIDIA NeMo Agent Toolkit (Web UI)High
- NVIDIA Jetson Linux (initrd command-line handling): An attacker with physical access and no credentials at all canCVE-2026-24154 · NVIDIA Jetson Linux (initrd command-line handling)High
- NVIDIA GPU firmware microcontroller (Falcon): A privileged user can craft microcode that the GPU's internalCVE-2021-23201 · NVIDIA GPU firmware microcontroller (Falcon)High
- NVIDIA GPU firmware microcontroller (Falcon): A privileged user can time a DMA write from the GPU's internalCVE-2021-23217 · NVIDIA GPU firmware microcontroller (Falcon)High
- NVIDIA DGX A100 - SBIOS / SMM firmware: An integer overflow in SmmCore, chainable from another bug, reaches SMM codeCVE-2022-31600 · NVIDIA DGX A100 - SBIOS / SMM firmwareHigh
- NVIDIA DGX A100 - SBIOS / SMM firmware: The SmiFlash SMM handler lets a privileged local user read, write and eraseCVE-2022-42276 · NVIDIA DGX A100 - SBIOS / SMM firmwareHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.