cbcvebase.
CVE-2025-23308
published 2025-09-24

CVE-2025-23308: NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm where an attacker may cause a heap-based buffer overflow by getting the user to run…

high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm where an attacker may cause a heap-based buffer overflow by getting the user to run nvdisasm on a malicious ELF file. A successful exploit of this vulnerability may lead to arbitrary code execution at the privilege level of the user running nvdisasm.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiannvidia-cuda-toolkit
msrccbl2_libxml2_2.9.13-1_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_libxml2_2.9.13-1_on_cbl_mariner_1.0
nvidiacuda_toolkit< 13.0.013.0.0
nvidianvidia_cuda_toolkit

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv7.8HIGH