First published: Sat Aug 31 2024(Updated: )
NVIDIA CUDA Toolkit contains a vulnerability in command `cuobjdump` where a user may cause a crash by passing in a malformed ELF file. A successful exploit of this vulnerability may cause an out of bounds read in the unprivileged process memory which could lead to a limited denial of service.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA CUDA Toolkit | <=12.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-0109 has not been explicitly rated but it presents a denial of service risk.
To fix CVE-2024-0109, update to the latest version of the NVIDIA CUDA Toolkit beyond version 12.6.0.
Any users of NVIDIA CUDA Toolkit versions up to and including 12.6.0 are affected by CVE-2024-0109.
CVE-2024-0109 is caused by passing a malformed ELF file to the `cuobjdump` command, resulting in an out of bounds read.
The potential impact of CVE-2024-0109 includes a denial of service condition due to process memory crashes.