NVIDIA CUDA Toolkit - nvdisasm: A null-pointer dereference on a malformed ELF crashes the disassembler
Impact
A null-pointer dereference on a malformed ELF crashes the disassembler. The realistic exposure is your build and profiling pipeline, not your runtime fleet: anything that automatically disassembles third-party fatbins, vendor kernels or model artifacts is running this parser on attacker-influenced input.
Who can reach it
Local, and requires a user or an automated job to run nvdisasm over an attacker-supplied file. CI jobs that inspect third-party CUDA binaries are the usual path.
What to do
Update the CUDA Toolkit package (bulletin 5577). Cost: effectively zero - userspace SDK only, no driver reload, no node drain, no running-job impact. Rebuild build/CI images and move on.
References
Related entries
- NVIDIA CUDA Toolkit - nvdisasm: out-of-bounds read on a malformed ELF crashes the disassemblerCVE-2025-23248 · NVIDIA CUDA Toolkit - nvdisasmLow
- NVIDIA CUDA Toolkit - nvdisasm: A heap-based buffer overflow on a malicious ELF gives arbitrary code executionCVE-2025-23308 · NVIDIA CUDA Toolkit - nvdisasmLow
- NVIDIA CUDA Toolkit - nvdisasm: An out-of-bounds write on a malicious ELF crashes the tool and corrupts heap stateCVE-2025-23338 · NVIDIA CUDA Toolkit - nvdisasmLow
- NVIDIA CUDA Toolkit - nvdisasm: Improper input validation on a malicious ELF crashes the disassemblerCVE-2024-0123 · NVIDIA CUDA Toolkit - nvdisasmLow
- NVIDIA CUDA Toolkit - nvdisasm: A use-after-free on a malformed ELF causes a crash and potentially worse dependingCVE-2024-0124 · NVIDIA CUDA Toolkit - nvdisasmLow
- GPU Display Driver: Info disclosure (OOB read)CVE-2024-0149 · GPU Display DriverLow
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.