Skip to finding
§
Medium
Boot chain — Physical
Confirmed

Physical access to a Jetson can turn NVIDIA's signed initrd into a pre-boot root shell and reveal the LUKS key.

NVIDIA removed eval and added field validation, but older vulnerable boot images remain acceptable.

Affects

NVIDIA Jetson Linux, the board-support package and boot stack for Jetson Xavier, Orin, and Thor embedded edge-AI systems.

What it enables

Secure Boot bypass, pre-boot root execution and LUKS key disclosure

Obtain physical access to the Jetson device before the encrypted root filesystem is unlocked→↓Place a crafted opt/nvidia/cryptluks file on the plaintext boot partition→↓Use boot-time Device Manager to select that partition and a serial console through the kernel command line→↓NVIDIA's signed initrd parses the attacker-controlled enc_dm_name and evaluates it as shell syntax→↓Receive an interactive root shell while the LUKS trusted application remains available→↓Query the trusted application and recover the root-filesystem LUKS key
Why this matters

This leads despite niche reach because one demonstrated device-in-hand path defeats both signed-boot execution integrity and encrypted-root secrecy, while the update does not make older vulnerable images unbootable.

Detail and 5 sources
Required access

Physical access to a Jetson device and its boot-time Device Manager

Affected versions

Jetson Linux 35.6.4, Jetson Linux 36.5.0, Jetson Linux 38.2.0, Jetson Linux 38.2.1, Jetson Linux 38.4.0, Jetson Linux 39.2.0, Jetson Linux 38.2.0 and 38.2.1, Jetson Linux 35.6.4 and earlier affected builds, Jetson Linux 36.5.0 and earlier affected builds

Proof of concept

Demonstrated by the researcher

An attacker with the device can place a crafted cryptluks file on the plaintext boot partition and use Device Manager to feed its enc_dm_name value into eval inside the signed initrd.

That produces a root shell before disk unlock, from which the LUKS trusted application discloses the encrypted root filesystem's key.

The shipped parser change removes eval and validates the field, but the platform enforces no anti-rollback and continues accepting pre-fix images.

Evidence
ONEKEY demonstrated the complete chain on a live device with an already-encrypted root filesystem and showed the resulting root shell and access to the LUKS keyONEKEY inspected the shipped fixes and found removal of eval plus field validationA public NVIDIA advisory or CVE assignment was available by the run cutoff
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Friday, September 4, 2026