NVIDIA NVDebug tool: NVDebug allows an actor to run code on the platform host as a non-privileged user, reaching code
CVSS 7.3CVE-2025-23344NVIDIA / GPU stackcurated
Impact
NVDebug allows an actor to run code on the platform host as a non-privileged user, reaching code execution and privilege escalation.
Who can reach it
Local, low privileges, user interaction. An unprivileged account on the platform host plus an operator running the tool.
What to do
Update NVDebug per bulletin 5696. Cost: trivial tool replacement, no drain.
References
Related entries
- NVIDIA NVDebug tool: The NVDebug diagnostic collector lets an actor gain access to a privileged account, reaching codeCVE-2025-23342 · NVIDIA NVDebug toolHigh
- NVIDIA NVDebug tool: NVDebug can be induced to write files into restricted components, reaching data tamperingCVE-2025-23343 · NVIDIA NVDebug toolHigh
- Cumulus Linux / NVOS: Command injection (local)CVE-2025-33181 · Cumulus Linux / NVOSHigh
- NVIDIA NeMo Framework: A predefined variable pulls in functionality from an untrusted control sphere, reaching codeCVE-2025-33205 · NVIDIA NeMo FrameworkHigh
- NVIDIA NeMo Framework: Loading a maliciously crafted model file bypasses the framework's control mechanisms and reachesCVE-2025-33212 · NVIDIA NeMo FrameworkHigh
- CUDA Toolkit: Local privilege escalation via command injection in toolkit utilitiesCVE-2025-33228 · CUDA ToolkitHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.