First published: Sat Aug 31 2024(Updated: )
NVIDIA CUDA Toolkit contains a vulnerability in command `cuobjdump` where a user may cause an out-of-bound write by passing in a malformed ELF file. A successful exploit of this vulnerability may lead to code execution or denial of service.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA CUDA Toolkit | <=12.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-0110 is classified as critical due to its potential for code execution.
To fix CVE-2024-0110, users should update to the latest version of the NVIDIA CUDA Toolkit beyond 12.6.0.
Exploitation of CVE-2024-0110 involves passing a malformed ELF file to the `cuobjdump` command.
Exploiting CVE-2024-0110 may result in code execution or denial of service.
NVIDIA CUDA Toolkit versions up to and including 12.6.0 are affected by CVE-2024-0110.