PT-2025-23013 · Nvidia+2 · Nvidia Cuda Toolkit+2
Dimitrios Tatsis
·
Published
2025-02-13
·
Updated
2025-11-20
·
CVE-2025-23247
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NVIDIA CUDA Toolkit (affected versions not specified)
Description
The NVIDIA CUDA Toolkit contains a flaw within the
cuobjdump binary. This issue stems from a failure to validate the length of a buffer when processing an ELF file. Exploitation involves providing a specially crafted, malformed ELF file, which could lead to arbitrary code execution. The cuobjdump tool may crash or execute unintended code due to this insufficient buffer length check. The vulnerability allows control over a buffer and its offset, potentially enabling arbitrary code execution.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Nvidia Cuda Toolkit
Red Os