NVIDIA CUDA Toolkit - cuobjdump: A null-pointer dereference from an unprivileged user crashes the tool
Impact
A null-pointer dereference from an unprivileged user crashes the tool. The realistic exposure is your build and profiling pipeline, not your runtime fleet: anything that automatically disassembles third-party fatbins, vendor kernels or model artifacts is running this parser on attacker-influenced input.
Who can reach it
Local, and requires a user or an automated job to run cuobjdump over an attacker-supplied file. CI jobs that inspect third-party CUDA binaries are the usual path.
What to do
Update the CUDA Toolkit package (bulletin 5661). Cost: effectively zero - userspace SDK only, no driver reload, no node drain, no running-job impact. Rebuild build/CI images and move on.
References
Related entries
- NVIDIA CUDA Toolkit - cuobjdump: An integer overflow reached by disassembling a corrupted fatbin gives remote codeCVE-2022-21821 · NVIDIA CUDA Toolkit - cuobjdumpHigh
- NVIDIA CUDA Toolkit - cuobjdump: out-of-bounds reads parsing malformed input filesCVE-2023-25512 · NVIDIA CUDA Toolkit - cuobjdumpMedium
- NVIDIA CUDA Toolkit - cuobjdump: A stack-based buffer overflow on a malformed input file yields limited denialCVE-2022-34667 · NVIDIA CUDA Toolkit - cuobjdumpMedium
- NVIDIA CUDA Toolkit - cuobjdump: A null-pointer dereference on a malformed binary crashes the toolCVE-2023-25510 · NVIDIA CUDA Toolkit - cuobjdumpLow
- NVIDIA CUDA Toolkit - cuobjdump: A division-by-zero on crafted input crashes the toolCVE-2023-25511 · NVIDIA CUDA Toolkit - cuobjdumpLow
- NVIDIA CUDA Toolkit - cuobjdump: An out-of-bounds read on a malformed ELF crashes the toolCVE-2025-23255 · NVIDIA CUDA Toolkit - cuobjdumpLow
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.