PT-2025-23013 · Nvidia+2 · Nvidia Cuda Toolkit+2

Dimitrios Tatsis

·

Published

2025-02-13

·

Updated

2025-11-20

·

CVE-2025-23247

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NVIDIA CUDA Toolkit (affected versions not specified)
Description The NVIDIA CUDA Toolkit contains a flaw within the cuobjdump binary. This issue stems from a failure to validate the length of a buffer when processing an ELF file. Exploitation involves providing a specially crafted, malformed ELF file, which could lead to arbitrary code execution. The cuobjdump tool may crash or execute unintended code due to this insufficient buffer length check. The vulnerability allows control over a buffer and its offset, potentially enabling arbitrary code execution.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Integer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-13649
CVE-2025-23247

Affected Products

Debian
Nvidia Cuda Toolkit
Red Os