GPU VulnDB

Database/NVIDIA / GPU stack

CUDA Toolkit: cuobjdump crashes on malformed ELF input, causing partial denial of service

CVSS 2.8CVE-2024-53878NVIDIA / GPU stack+1 more CVEscurated

Impact

A local user who can get cuobjdump to parse an attacker-supplied ELF/cubin file can crash the tool, a partial denial of service on the machine doing the parsing (no confidentiality or integrity impact, CVSS 3.1 base 2.8, AV:L/AC:L/PR:L/UI:R). NVIDIA split this one cuobjdump input-validation crash class across 2 CVE ids in bulletin 5594 (CVE-2024-53878, CVE-2024-53879); both are fixed by the same release, so they are one action for an operator. Relevant mainly to CI and build hosts that run cuobjdump over untrusted model or kernel artifacts.

Who can reach it

Malicious artifact

What to do

Upgrade CUDA Toolkit to 12.8 or later and rebuild any container base images that ship the toolkit; this single upgrade covers both ids. Where cuobjdump is run over untrusted artifacts, do it in a sandboxed or disposable build step.

Also covers 1 CVE

The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.

CVE-2024-53879

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.