CVE-2024-0123
published 2024-10-03CVE-2024-0123: NVIDIA CUDA toolkit for Windows and Linux contains a vulnerability in the nvdisasm command line tool where an attacker may cause an improper validation in…
PriorityP48low3.3CVSS 3.1
AVLACLPRNUIRSUCNINAL
EPSS
0.21%
10.6th percentile
NVIDIA CUDA toolkit for Windows and Linux contains a vulnerability in the nvdisasm command line tool where an attacker may cause an improper validation in input issue by tricking the user into running nvdisasm on a malicious ELF file. A successful exploit of this vulnerability may lead to denial of service.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nvidia-cuda-toolkit | — | — |
| nvidia | cuda_toolkit | <= 12.6.2 | — |
| nvidia | cuda_toolkit | — | — |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
NVIDIA CUDA Toolkit: improper input validation may lead to DoS
vendor_redhat·2024-10-03·CVSS 3.3
CVE-2024-0123 [LOW] CWE-1285 NVIDIA CUDA Toolkit: improper input validation may lead to DoS
NVIDIA CUDA Toolkit: improper input validation may lead to DoS
NVIDIA CUDA toolkit for Windows and Linux contains a vulnerability in the nvdisasm command line tool where an attacker may cause an improper validation in input issue by tricking the user into running nvdisasm on a malicious ELF file. A successful exploit of this vulnerability may lead to denial of service.
A flaw was found in the NVIDIA CUDA toolkit. This issue may allow an attacker to cause an improper validation in input issue via the nvdisasm command line tool by tricking the user into running nvdisasm on a malicious ELF file, leading to a denial of service.
Package: openshift-lightspeed-beta/lightspeed-service-api-rhel9 (OpenShift Lightspeed) - Fix deferred
Package: rhelai1/bootc-nvidia-rhel9 (Red Hat Enterprise Linux
Debian
CVE-2024-0123: nvidia-cuda-toolkit - NVIDIA CUDA toolkit for Windows and Linux contains a vulnerability in the nvdisa...
vendor_debian·2024·CVSS 3.3
CVE-2024-0123 [LOW] CVE-2024-0123: nvidia-cuda-toolkit - NVIDIA CUDA toolkit for Windows and Linux contains a vulnerability in the nvdisa...
NVIDIA CUDA toolkit for Windows and Linux contains a vulnerability in the nvdisasm command line tool where an attacker may cause an improper validation in input issue by tricking the user into running nvdisasm on a malicious ELF file. A successful exploit of this vulnerability may lead to denial of service.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-ff23-px5j-g8qq: NVIDIA CUDA toolkit for Windows and Linux contains a vulnerability in the nvdisasm command line tool where an attacker may cause an improper validatio
ghsa_unreviewed·2024-10-03
CVE-2024-0123 [LOW] CWE-1285 GHSA-ff23-px5j-g8qq: NVIDIA CUDA toolkit for Windows and Linux contains a vulnerability in the nvdisasm command line tool where an attacker may cause an improper validatio
NVIDIA CUDA toolkit for Windows and Linux contains a vulnerability in the nvdisasm command line tool where an attacker may cause an improper validation in input issue by tricking the user into running nvdisasm on a malicious ELF file. A successful exploit of this vulnerability may lead to denial of service.
OSV
CVE-2024-0123: NVIDIA CUDA toolkit for Windows and Linux contains a vulnerability in the nvdisasm command line tool where an attacker may cause an improper validatio
osv·2024-10-03·CVSS 3.3
CVE-2024-0123 [LOW] CVE-2024-0123: NVIDIA CUDA toolkit for Windows and Linux contains a vulnerability in the nvdisasm command line tool where an attacker may cause an improper validatio
NVIDIA CUDA toolkit for Windows and Linux contains a vulnerability in the nvdisasm command line tool where an attacker may cause an improper validation in input issue by tricking the user into running nvdisasm on a malicious ELF file. A successful exploit of this vulnerability may lead to denial of service.
No detection rules found.
2024-10-03
Published