CUDA Toolkit (cuobjdump): out-of-bounds reads parsing malformed ELF files cause partial denial of service
Impact
A local user who can get cuobjdump to open an attacker-supplied ELF/cubin file can crash it (partial DoS, CVSS 3.3, AV:L/UI:R, no confidentiality or integrity loss). NVIDIA split this across 5 ids (CVE-2024-53870, -53872, -53873, -53874, -53875) as separate internal defects in the same parser; there is no operational difference between them. Only relevant where untrusted binaries are disassembled, e.g. build or CI tooling that inspects third-party cubins.
Who can reach it
Malicious cubin/model artifact
What to do
Upgrade to CUDA Toolkit 12.8 on Windows and Linux and rebuild any container base images that ship cuobjdump; a single upgrade closes all five.
Also covers 4 CVEs
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- CUDA Toolkit (nvdisasm): out-of-bounds reads parsing malformed ELF files cause partial denial of serviceCVE-2024-53871 · CUDA ToolkitLow
- CUDA Toolkit: DoS (null deref)CVE-2024-53877 · CUDA ToolkitLow
- CUDA Toolkit: Info disclosure (buffer over-read)CVE-2025-23271 · CUDA ToolkitLow
- CUDA Toolkit: cuobjdump crashes on malformed ELF input, causing partial denial of serviceCVE-2024-53878 · CUDA ToolkitLow
- CUDA Toolkit: DoS (division by zero)CVE-2025-23273 · CUDA ToolkitLow
- CUDA Toolkit: Local privilege escalation via command injection in toolkit utilitiesCVE-2025-33228 · CUDA ToolkitHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.