CVE-2024-0111 — Improper Validation of Specified Quantity in Input in Nvidia Cuda Toolkit
Severity
4.4MEDIUMNVD
EPSS
0.1%
top 76.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 31
Description
NVIDIA CUDA Toolkit contains a vulnerability in command 'cuobjdump' where a user may cause a crash or produce incorrect output by passing a malformed ELF file. A successful exploit of this vulnerability may lead to a limited denial of service or data tampering.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:LExploitability: 1.8 | Impact: 2.5
Affected Packages2 packages
🔴Vulnerability Details
3GHSA▶
GHSA-qccm-7jq2-92v7: NVIDIA CUDA Toolkit contains a vulnerability in command 'cuobjdump' where a user may cause a crash or produce incorrect output by passing a malformed↗2024-08-31
CVEList▶
CVE-2024-0111: NVIDIA CUDA Toolkit contains a vulnerability in command 'cuobjdump' where a user may cause a crash or produce incorrect output by passing a malformed↗2024-08-31
OSV▶
CVE-2024-0111: NVIDIA CUDA Toolkit contains a vulnerability in command 'cuobjdump' where a user may cause a crash or produce incorrect output by passing a malformed↗2024-08-31
💥Exploits & PoCs
1Nuclei▶
FastChat - Open Redirect