CVE-2025-23308 Details
Description
NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm where an attacker may cause a heap-based buffer overflow by getting the user to run nvdisasm on a malicious ELF file. A successful exploit of this vulnerability may lead to arbitrary code execution at the privilege level of the user running nvdisasm.
A heap-based buffer overflow vulnerability has been identified in the NVIDIA CUDA Toolkit's nvdisasm component, present in all versions prior to 13.0. This vulnerability allows an attacker to execute arbitrary code at the privilege level of the user running nvdisasm, by manipulating the user into processing a malicious ELF file with the tool.
Users are advised to upgrade to NVIDIA CUDA Toolkit 13.0 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 25, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2204 | CVE | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-23308 | [email protected] | Third Party Advisory |
| https://nvidia.custhelp.com/app/answers/detail/a_id/5661 | [email protected] | Vendor Advisory |
| https://www.cve.org/CVERecord?id=CVE-2025-23308 | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-122 | Heap-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nvidia cuda toolkit | < 13.0.0 |
CPE
Remediation
| |
| linux linux kernel | All versions |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 3, 2025 | CVE Modified | CVE |
| Oct 6, 2025 | Initial Analysis | [email protected] |
| Sep 24, 2025 | New CVE Received | [email protected] |