CUDA Toolkit: Local privilege escalation via command injection in toolkit utilities
Impact
A local user can inject commands that run with the privileges of the invoking toolkit process, giving local privilege escalation; NVIDIA split this across 2 CVE ids in advisory 5755, but they are the same flaw class with the same fix.
Who can reach it
Local user running toolkit binaries
What to do
Upgrade the CUDA Toolkit to the fixed version listed in NVIDIA advisory 5755 and rebuild any base images that embed it - this clears both ids at once.
Also covers 1 CVE
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- CUDA Toolkit: Code exec via untrusted library loadCVE-2025-33229 · CUDA ToolkitHigh
- CUDA Toolkit: Memory-safety issueCVE-2024-0111 · CUDA ToolkitMedium
- CUDA Toolkit: Code exec via path manipulation on library loadCVE-2025-33231 · CUDA ToolkitMedium
- CUDA Toolkit: Info disclosure / DoS (buffer over-read)CVE-2025-23272 · CUDA ToolkitMedium
- CUDA Toolkit: Info disclosure (buffer over-read)CVE-2025-23274 · CUDA ToolkitMedium
- CUDA Toolkit: DoS / info disclosure (buffer over-read in cuobjdump)CVE-2023-0193 · CUDA ToolkitMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.