NVIDIA CUDA Toolkit - cuobjdump: A null-pointer dereference on a malformed binary crashes the tool
Impact
A null-pointer dereference on a malformed binary crashes the tool. The realistic exposure is your build and profiling pipeline, not your runtime fleet: anything that automatically disassembles third-party fatbins, vendor kernels or model artifacts is running this parser on attacker-influenced input.
Who can reach it
Local, and requires a user or an automated job to run cuobjdump over an attacker-supplied file. CI jobs that inspect third-party CUDA binaries are the usual path.
What to do
Update the CUDA Toolkit package (bulletin 5456). Cost: effectively zero - userspace SDK only, no driver reload, no node drain, no running-job impact. Rebuild build/CI images and move on.
References
Related entries
- NVIDIA CUDA Toolkit - cuobjdump: A division-by-zero on crafted input crashes the toolCVE-2023-25511 · NVIDIA CUDA Toolkit - cuobjdumpLow
- NVIDIA CUDA Toolkit - cuobjdump: An out-of-bounds read on a malformed ELF crashes the toolCVE-2025-23255 · NVIDIA CUDA Toolkit - cuobjdumpLow
- NVIDIA CUDA Toolkit - cuobjdump: A stack-based buffer overflow on a malicious ELF gives arbitrary code executionCVE-2025-23339 · NVIDIA CUDA Toolkit - cuobjdumpLow
- NVIDIA CUDA Toolkit - cuobjdump: A null-pointer dereference from an unprivileged user crashes the toolCVE-2025-23346 · NVIDIA CUDA Toolkit - cuobjdumpLow
- NVIDIA CUDA Toolkit - cuobjdump: An integer overflow reached by disassembling a corrupted fatbin gives remote codeCVE-2022-21821 · NVIDIA CUDA Toolkit - cuobjdumpHigh
- NVIDIA CUDA Toolkit - cuobjdump: out-of-bounds reads parsing malformed input filesCVE-2023-25512 · NVIDIA CUDA Toolkit - cuobjdumpMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.