PublicCVE

CVE-2023-25523

LOW3.3Memory safety

Description

NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the nvdisasm binary file, where an attacker may cause a NULL pointer dereference by providing a user with a malformed ELF file. A successful exploit of this vulnerability may lead to a partial denial of service.

CVSS breakdown

CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
Low

Affected products

  • NVIDIA / CUDA ToolkitAll versions prior to CUDA Toolkit v12.2 – All versions prior to CUDA Toolkit v12.2