CVE-2025-23308: Buffer Overflow
NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm where an attacker may cause a heap-based buffer overflow by getting the user to run nvdisasm on a malicious ELF file. A successful exploit of this vulnerability may lead to arbitrary code execution at the privilege level of the user running nvdisasm.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23308?
The severity of CVE-2025-23308 is considered high due to the potential for arbitrary code execution.
How do I fix CVE-2025-23308?
To fix CVE-2025-23308, update to the latest version of the NVIDIA CUDA Toolkit that addresses this vulnerability.
What is the impact of CVE-2025-23308?
The impact of CVE-2025-23308 includes the possibility of an attacker executing arbitrary code at the privilege level of the user running nvdisasm.
Who is affected by CVE-2025-23308?
All users of the NVIDIA CUDA Toolkit who run nvdisasm on malicious ELF files are potentially affected by CVE-2025-23308.
What is nvdisasm in the context of CVE-2025-23308?
In the context of CVE-2025-23308, nvdisasm is a disassembler for NVIDIA's GPU binary files, which is vulnerable to buffer overflow exploits.