CVE-2024-53870
published 2025-02-25CVE-2024-53870: NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by passing a malformed…
PriorityP46low3.3CVSS 3.1
AVLACLPRNUIRSUCNINAL
EPSS
0.24%
15.4th percentile
NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by passing a malformed ELF file to cuobjdump. A successful exploit of this vulnerability might lead to a partial denial of service.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nvidia-cuda-toolkit | — | — |
| nvidia | cuda_toolkit | < 12.8.0 | 12.8.0 |
| nvidia | cuda_toolkit | — | — |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
osv3.3LOW
vendor_debian3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2024-53870: nvidia-cuda-toolkit - NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump ...
vendor_debian·2024·CVSS 3.3
CVE-2024-53870 [LOW] CVE-2024-53870: nvidia-cuda-toolkit - NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump ...
NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by passing a malformed ELF file to cuobjdump. A successful exploit of this vulnerability might lead to a partial denial of service.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-jv6c-2mw3-h322: NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by passing a ma
ghsa_unreviewed·2025-02-25
CVE-2024-53870 [LOW] CWE-125 GHSA-jv6c-2mw3-h322: NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by passing a ma
NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by passing a malformed ELF file to cuobjdump. A successful exploit of this vulnerability might lead to a partial denial of service.
OSV
CVE-2024-53870: NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by passing a ma
osv·2025-02-25·CVSS 3.3
CVE-2024-53870 [LOW] CVE-2024-53870: NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by passing a ma
NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by passing a malformed ELF file to cuobjdump. A successful exploit of this vulnerability might lead to a partial denial of service.
No detection rules found.
No public exploits indexed.
Unit42
Multiple Vulnerabilities Discovered in NVIDIA CUDA Toolkit
blogs_unit42·2025-02-19·CVSS 3.3
CVE-2024-53870 [LOW] Multiple Vulnerabilities Discovered in NVIDIA CUDA Toolkit
## Executive Summary
This article reviews nine vulnerabilities we recently discovered in two utilities called cuobjdump and nvdisasm, both from NVIDIA's Compute Unified Device Architecture (CUDA) Toolkit. We have coordinated with NVIDIA, and the company has released an update in February 2025 to address these issues.
The vulnerabilities are tracked as the following Common Vulnerabilities and Exposures (CVEs):
- CVE-2024-53870
- CVE-2024-53871
- CVE-2024-53872
- CVE-2024-53873
- CVE-2024-53874
- CVE-2024-53875
- CVE-2024-53876
- CVE-2024-53877
- CVE-2024-53878
Introduced in 2006, CUDA is a parallel computing platform and programming model. As part of NVIDIA's CUDA Toolkit, developers use the cuobjdump and nvdisasm tools to analyze CUDA binary files used in programs to run on NVIDIA grap
Unit42
Multiple Vulnerabilities Discovered in NVIDIA CUDA Toolkit
blogs_unit42·2025-02-19·CVSS 3.3
CVE-2024-53870 [LOW] Multiple Vulnerabilities Discovered in NVIDIA CUDA Toolkit
## Multiple Vulnerabilities Discovered in NVIDIA CUDA Toolkit
Kai Lu
Published: February 19, 2025
Threat Research
Vulnerabilities
CUDA
Cuobjdump
CVE-2024-53870
CVE-2024-53871
CVE-2024-53872
CVE-2024-53873
CVE-2024-53874
CVE-2024-53875
CVE-2024-53876
CVE-2024-53877
CVE-2024-53878
Nvdisasm
NVIDIA
## Executive Summary
This article reviews nine vulnerabilities we recently discovered in two utilities called cuobjdump and nvdisasm , both from NVIDIA's Compute Unified Device Architecture (CUDA) Toolkit. We have coordinated with NVIDIA, and the company has released an update in February 2025 to address these issues.
The vulnerabilities are tracked as the following Common Vulnerabilities and Exposures (CVEs):
CVE-2024-53870
CVE-2024-53871
CVE-2024-53872
CVE-2024-53873
CV
2025-02-25
Published