GPU VulnDB

Database/NVIDIA / GPU stack

NVIDIA nvJPEG2000 library: Improper input validation on a crafted JPEG2000 file causes a partial denial of service

CVE-2023-31028NVIDIA / GPU stackcurated

Impact

Improper input validation on a crafted JPEG2000 file causes a partial denial of service in the decoding library. Low severity on its own, but nvJPEG2000 sits inside DALI and medical/geospatial imaging pipelines that ingest customer files by design, so the untrusted-input assumption is real.

Who can reach it

Local, requires the library to decode an attacker-supplied image. Any data-loading pipeline that accepts tenant or customer imagery is the delivery path.

What to do

Update the nvJPEG2000 library per bulletin 5517 and rebuild the images that link it. Cost: package update and job restart only; no driver or firmware change.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.