NVIDIA CUDA Toolkit - cuobjdump: out-of-bounds reads parsing malformed input files
Impact
A malformed fatbin or object file fed to cuobjdump triggers an out-of-bounds read that can reach limited code execution and information disclosure. NVIDIA split this across 3 ids (CVE-2023-25512/25513/25514) for separate read paths in the same parser, all at CVSS 5.3. Exposure is the build and profiling pipeline rather than the runtime fleet: anything that automatically disassembles third-party fatbins, vendor kernels or model artifacts is running this parser on attacker-influenced input.
Who can reach it
Local, and requires a user or an automated job to run cuobjdump over an attacker-supplied file. CI jobs that inspect third-party CUDA binaries are the usual path.
What to do
Update the CUDA Toolkit package per bulletin 5456 - one update closes all three. Cost: effectively zero, userspace SDK only, no driver reload, no node drain, no running-job impact. Rebuild build/CI images and move on.
Also covers 2 CVEs
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- NVIDIA CUDA Toolkit - cuobjdump: A stack-based buffer overflow on a malformed input file yields limited denialCVE-2022-34667 · NVIDIA CUDA Toolkit - cuobjdumpMedium
- NVIDIA CUDA Toolkit - cuobjdump: A null-pointer dereference on a malformed binary crashes the toolCVE-2023-25510 · NVIDIA CUDA Toolkit - cuobjdumpLow
- NVIDIA CUDA Toolkit - cuobjdump: A division-by-zero on crafted input crashes the toolCVE-2023-25511 · NVIDIA CUDA Toolkit - cuobjdumpLow
- NVIDIA CUDA Toolkit - cuobjdump: An out-of-bounds read on a malformed ELF crashes the toolCVE-2025-23255 · NVIDIA CUDA Toolkit - cuobjdumpLow
- NVIDIA CUDA Toolkit - cuobjdump: A stack-based buffer overflow on a malicious ELF gives arbitrary code executionCVE-2025-23339 · NVIDIA CUDA Toolkit - cuobjdumpLow
- NVIDIA CUDA Toolkit - cuobjdump: A null-pointer dereference from an unprivileged user crashes the toolCVE-2025-23346 · NVIDIA CUDA Toolkit - cuobjdumpLow
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.