CVE-2025-23339

EUVD-2025-30965
NVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump where an attacker may cause a stack-based buffer overflow by getting the user to run cuobjdump on a malicious ELF file. A successful exploit of this vulnerability may lead to arbitrary code execution at the privilege level of the user running 
cuobjdump.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.3 LOW
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 23.33%
Affected Products (NVD)
VendorProductVersion
nvidiacuda_toolkit
𝑥
< 13.0.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
nvidia-cuda-toolkit
bookworm
no-dsa
bookworm/non-free
vulnerable
bullseye/non-free
vulnerable
forky/non-free
vulnerable
sid/non-free
vulnerable
trixie
no-dsa
trixie/non-free
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
nvidia-cuda-toolkit
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
plucky
ignored
questing
ignored
resolute
needs-triage
xenial
needs-triage