CVE-2024-53878
published 2025-02-25CVE-2024-53878: NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the cuobjdump binary, where a user could cause a crash by passing a malformed ELF file to…
PriorityP45low2.8CVSS 3.1
AVLACLPRLUIRSUCNINAL
EPSS
0.23%
13.2th percentile
NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the cuobjdump binary, where a user could cause a crash by passing a malformed ELF file to cuobjdump. A successful exploit of this vulnerability might lead to a partial denial of service.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nvidia-cuda-toolkit | — | — |
| nvidia | cuda_toolkit | < 12.8.0 | 12.8.0 |
| nvidia | cuda_toolkit | — | — |
CVSS provenance
nvdv3.12.8LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
osv2.8LOW
vendor_debian2.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
NVIDIA CUDA Toolkit on Linux/Windows ELF File improper validation of specified quantity in input (Nessus ID 314575)
vuldb·2026-05-14·CVSS 2.8
CVE-2024-53878 [LOW] NVIDIA CUDA Toolkit on Linux/Windows ELF File improper validation of specified quantity in input (Nessus ID 314575)
A vulnerability classified as problematic has been found in NVIDIA CUDA Toolkit on Linux/Windows. The affected element is an unknown function of the component ELF File Handler. Performing a manipulation results in improper validation of specified quantity in input.
This vulnerability is identified as CVE-2024-53878. The attack is only possible with local access. There is not any exploit available.
OSV
CVE-2024-53878: NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the cuobjdump binary, where a user could cause a crash by passing a malformed EL
osv·2025-02-25·CVSS 2.8
CVE-2024-53878 [LOW] CVE-2024-53878: NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the cuobjdump binary, where a user could cause a crash by passing a malformed EL
NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the cuobjdump binary, where a user could cause a crash by passing a malformed ELF file to cuobjdump. A successful exploit of this vulnerability might lead to a partial denial of service.
GHSA
GHSA-m95x-5www-9p45: NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the cuobjdump binary, where a user could cause a crash by passing a malformed EL
ghsa_unreviewed·2025-02-25
CVE-2024-53878 [LOW] CWE-1284 GHSA-m95x-5www-9p45: NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the cuobjdump binary, where a user could cause a crash by passing a malformed EL
NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the cuobjdump binary, where a user could cause a crash by passing a malformed ELF file to cuobjdump. A successful exploit of this vulnerability might lead to a partial denial of service.
Debian
CVE-2024-53878: nvidia-cuda-toolkit - NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the cuobjd...
vendor_debian·2024·CVSS 2.8
CVE-2024-53878 [LOW] CVE-2024-53878: nvidia-cuda-toolkit - NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the cuobjd...
NVIDIA CUDA toolkit for Linux and Windows contains a vulnerability in the cuobjdump binary, where a user could cause a crash by passing a malformed ELF file to cuobjdump. A successful exploit of this vulnerability might lead to a partial denial of service.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
Unit42
Multiple Vulnerabilities Discovered in NVIDIA CUDA Toolkit
blogs_unit42·2025-02-19·CVSS 3.3
CVE-2024-53870 [LOW] Multiple Vulnerabilities Discovered in NVIDIA CUDA Toolkit
## Executive Summary
This article reviews nine vulnerabilities we recently discovered in two utilities called cuobjdump and nvdisasm, both from NVIDIA's Compute Unified Device Architecture (CUDA) Toolkit. We have coordinated with NVIDIA, and the company has released an update in February 2025 to address these issues.
The vulnerabilities are tracked as the following Common Vulnerabilities and Exposures (CVEs):
- CVE-2024-53870
- CVE-2024-53871
- CVE-2024-53872
- CVE-2024-53873
- CVE-2024-53874
- CVE-2024-53875
- CVE-2024-53876
- CVE-2024-53877
- CVE-2024-53878
Introduced in 2006, CUDA is a parallel computing platform and programming model. As part of NVIDIA's CUDA Toolkit, developers use the cuobjdump and nvdisasm tools to analyze CUDA binary files used in programs to run on NVIDIA grap
Unit42
Multiple Vulnerabilities Discovered in NVIDIA CUDA Toolkit
blogs_unit42·2025-02-19·CVSS 3.3
CVE-2024-53870 [LOW] Multiple Vulnerabilities Discovered in NVIDIA CUDA Toolkit
## Multiple Vulnerabilities Discovered in NVIDIA CUDA Toolkit
Kai Lu
Published: February 19, 2025
Threat Research
Vulnerabilities
CUDA
Cuobjdump
CVE-2024-53870
CVE-2024-53871
CVE-2024-53872
CVE-2024-53873
CVE-2024-53874
CVE-2024-53875
CVE-2024-53876
CVE-2024-53877
CVE-2024-53878
Nvdisasm
NVIDIA
## Executive Summary
This article reviews nine vulnerabilities we recently discovered in two utilities called cuobjdump and nvdisasm , both from NVIDIA's Compute Unified Device Architecture (CUDA) Toolkit. We have coordinated with NVIDIA, and the company has released an update in February 2025 to address these issues.
The vulnerabilities are tracked as the following Common Vulnerabilities and Exposures (CVEs):
CVE-2024-53870
CVE-2024-53871
CVE-2024-53872
CVE-2024-53873
CV
2025-02-25
Published