NVIDIA CUDA Toolkit - nvdisasm: An out-of-bounds write on a malicious ELF crashes the tool and corrupts heap state
Impact
An out-of-bounds write on a malicious ELF crashes the tool and corrupts heap state. The realistic exposure is your build and profiling pipeline, not your runtime fleet: anything that automatically disassembles third-party fatbins, vendor kernels or model artifacts is running this parser on attacker-influenced input.
Who can reach it
Local, and requires a user or an automated job to run nvdisasm over an attacker-supplied file. CI jobs that inspect third-party CUDA binaries are the usual path.
What to do
Update the CUDA Toolkit package (bulletin 5661). Cost: effectively zero - userspace SDK only, no driver reload, no node drain, no running-job impact. Rebuild build/CI images and move on.
References
Related entries
- NVIDIA CUDA Toolkit - nvdisasm: Improper input validation on a malicious ELF crashes the disassemblerCVE-2024-0123 · NVIDIA CUDA Toolkit - nvdisasmLow
- NVIDIA CUDA Toolkit - nvdisasm: A use-after-free on a malformed ELF causes a crash and potentially worse dependingCVE-2024-0124 · NVIDIA CUDA Toolkit - nvdisasmLow
- NVIDIA CUDA Toolkit - nvdisasm: A null-pointer dereference on a malformed ELF crashes the disassemblerCVE-2024-0125 · NVIDIA CUDA Toolkit - nvdisasmLow
- NVIDIA CUDA Toolkit - nvdisasm: out-of-bounds read on a malformed ELF crashes the disassemblerCVE-2025-23248 · NVIDIA CUDA Toolkit - nvdisasmLow
- NVIDIA CUDA Toolkit - nvdisasm: A heap-based buffer overflow on a malicious ELF gives arbitrary code executionCVE-2025-23308 · NVIDIA CUDA Toolkit - nvdisasmLow
- NVIDIA CUDA Toolkit - cuobjdump: A stack-based buffer overflow on a malicious ELF gives arbitrary code executionCVE-2025-23339 · NVIDIA CUDA Toolkit - cuobjdumpLow
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.