CVE-2024-0124: Use After Free
Published Oct 3, 2024
·Updated
NVIDIA CUDA Toolkit for Windows and Linux contains a vulnerability in the nvdisam command line tool, where a user can cause nvdisasm to read freed memory by running it on a malformed ELF file. A successful exploit of this vulnerability might lead to a limited denial of service.
Affected Software
4 affected components
Nvidia CUDA Toolkit
All of the following
Nvidia CUDA Toolkit<12.6.2
Any of the following
Linux Linux kernel
Microsoft Windows
Event History
Oct 3, 2024
CVE Published
via MITRE·04:45 PM
Data Sourced
via MITRE·04:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-0124?
CVE-2024-0124 is classified with a limited denial of service impact.
2
How do I fix CVE-2024-0124?
To mitigate CVE-2024-0124, ensure that you are using the latest version of the NVIDIA CUDA Toolkit that includes the necessary patches.
3
What component is affected in CVE-2024-0124?
CVE-2024-0124 affects the nvdisasm command line tool in the NVIDIA CUDA Toolkit.
4
Can CVE-2024-0124 be exploited through any ELF file?
CVE-2024-0124 can be exploited by running nvdisasm on a specifically malformed ELF file.
5
What could be the consequence of exploiting CVE-2024-0124?
Exploiting CVE-2024-0124 may lead to a limited denial of service.