CVE-2024-0110: High severity nvidia cuda toolkit vulnerability
Published Aug 31, 2024
·Updated
NVIDIA CUDA Toolkit contains a vulnerability in command cuobjdump where a user may cause an out-of-bound write by passing in a malformed ELF file. A successful exploit of this vulnerability may lead to code execution or denial of service.
Affected Software
1 affected component
Nvidia CUDA Toolkit<=12.6.0
Event History
Aug 31, 2024
CVE Published
via MITRE·08:27 AM
Data Sourced
via MITRE·08:27 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-0110?
The severity of CVE-2024-0110 is classified as critical due to its potential for code execution.
2
How do I fix CVE-2024-0110?
To fix CVE-2024-0110, users should update to the latest version of the NVIDIA CUDA Toolkit beyond 12.6.0.
3
What exploitation methods exist for CVE-2024-0110?
Exploitation of CVE-2024-0110 involves passing a malformed ELF file to the `cuobjdump` command.
4
What are the consequences of exploiting CVE-2024-0110?
Exploiting CVE-2024-0110 may result in code execution or denial of service.
5
Which versions of the NVIDIA CUDA Toolkit are affected by CVE-2024-0110?
NVIDIA CUDA Toolkit versions up to and including 12.6.0 are affected by CVE-2024-0110.