CUDA Toolkit: cuobjdump crashes on malformed ELF input, causing partial denial of service
Impact
A local user who can get cuobjdump to parse an attacker-supplied ELF/cubin file can crash the tool, a partial denial of service on the machine doing the parsing (no confidentiality or integrity impact, CVSS 3.1 base 2.8, AV:L/AC:L/PR:L/UI:R). NVIDIA split this one cuobjdump input-validation crash class across 2 CVE ids in bulletin 5594 (CVE-2024-53878, CVE-2024-53879); both are fixed by the same release, so they are one action for an operator. Relevant mainly to CI and build hosts that run cuobjdump over untrusted model or kernel artifacts.
Who can reach it
Malicious artifact
What to do
Upgrade CUDA Toolkit to 12.8 or later and rebuild any container base images that ship the toolkit; this single upgrade covers both ids. Where cuobjdump is run over untrusted artifacts, do it in a sandboxed or disposable build step.
Also covers 1 CVE
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- CUDA Toolkit: DoS (division by zero)CVE-2025-23273 · CUDA ToolkitLow
- CUDA Toolkit: Local privilege escalation via command injection in toolkit utilitiesCVE-2025-33228 · CUDA ToolkitHigh
- CUDA Toolkit: Code exec via untrusted library loadCVE-2025-33229 · CUDA ToolkitHigh
- CUDA Toolkit: Memory-safety issueCVE-2024-0111 · CUDA ToolkitMedium
- CUDA Toolkit: Code exec via path manipulation on library loadCVE-2025-33231 · CUDA ToolkitMedium
- CUDA Toolkit: Info disclosure / DoS (buffer over-read)CVE-2025-23272 · CUDA ToolkitMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.