CVE-2025-23339 Details
Description
NVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump where an attacker may cause a stack-based buffer overflow by getting the user to run cuobjdump on a malicious ELF file. A successful exploit of this vulnerability may lead to arbitrary code execution at the privilege level of the user running cuobjdump.
A stack-based buffer overflow vulnerability has been identified in the NVIDIA CUDA Toolkit cuobjdump component, present in all versions prior to CUDA Toolkit 13.0. This vulnerability allows an attacker to execute arbitrary code at the privilege level of the user running cuobjdump, by manipulating the user to process a malicious ELF file. The issue arises from improper handling of the file, leading to the potential for exploitation.
Users are advised to upgrade to NVIDIA CUDA Toolkit 13.0 or later. The latest version can be downloaded from the CUDA Toolkit Downloads page.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 25, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2155 | CVE | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-23339 | [email protected] | Third Party Advisory |
| https://nvidia.custhelp.com/app/answers/detail/a_id/5661 | [email protected] | Vendor Advisory |
| https://www.cve.org/CVERecord?id=CVE-2025-23339 | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nvidia cuda toolkit | < 13.0.0 |
CPE
Remediation
| |
| linux linux kernel | All versions |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 26, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 3, 2025 | CVE Modified | CVE |
| Oct 6, 2025 | Initial Analysis | [email protected] |
| Sep 24, 2025 | New CVE Received | [email protected] |