Physical access to a Jetson can turn NVIDIA's signed initrd into a pre-boot root shell and reveal the LUKS key.
NVIDIA removed eval and added field validation, but older vulnerable boot images remain acceptable.
NVIDIA Jetson Linux, the board-support package and boot stack for Jetson Xavier, Orin, and Thor embedded edge-AI systems.
Secure Boot bypass, pre-boot root execution and LUKS key disclosure
This leads despite niche reach because one demonstrated device-in-hand path defeats both signed-boot execution integrity and encrypted-root secrecy, while the update does not make older vulnerable images unbootable.
Detail and 5 sources
An attacker with the device can place a crafted cryptluks file on the plaintext boot partition and use Device Manager to feed its enc_dm_name value into eval inside the signed initrd.
That produces a root shell before disk unlock, from which the LUKS trusted application discloses the encrypted root filesystem's key.
The shipped parser change removes eval and validates the field, but the platform enforces no anti-rollback and continues accepting pre-fix images.
- access:physical:device-in-hand
- the attacker holds the device
- state:device:bfu
- before first unlock
- access:physical:port
- access to an external port
- Pre-fix images still accepted
- Yes
- Reaches end-of-life hardware
- Yes
Assessment based on public material available through 2026-09-04.