GPU VulnDB

Database/NVIDIA / GPU stack

CUDA Toolkit (nvdisasm): out-of-bounds reads parsing malformed ELF files cause partial denial of service

CVSS 3.3CVE-2024-53871NVIDIA / GPU stack+1 more CVEscurated

Impact

A local user who can get nvdisasm to disassemble an attacker-supplied ELF file can crash it (partial DoS, CVSS 3.3, AV:L/UI:R). NVIDIA split this across 2 ids (CVE-2024-53871, -53876) as separate internal defects in the same parser; the operator response is identical for both.

Who can reach it

Malicious cubin/model artifact

What to do

Upgrade to CUDA Toolkit 12.8 on Windows and Linux and rebuild any container base images that ship nvdisasm; a single upgrade closes both.

Also covers 1 CVE

The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.

CVE-2024-53876

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.