NVIDIA CUDA Toolkit Heap-Based Buffer Overflow Vulnerability in nvdisasm Allowing Arbitrary Code Execution

Vulnerability

A heap-based buffer overflow vulnerability has been identified in the NVIDIA CUDA Toolkit's nvdisasm component, present in all versions prior to 13.0. This vulnerability allows an attacker to execute arbitrary code at the privilege level of the user running nvdisasm, by manipulating the user into processing a malicious ELF file with the tool.

Impact

Exploitation of this vulnerability could lead to arbitrary code execution, with the executed code running at the same privilege level as the user who initiated nvdisasm.

Remediation

Users are advised to upgrade to NVIDIA CUDA Toolkit 13.0 or later.

Added: Sep 24, 2025, 2:26 PM
Updated: Sep 24, 2025, 9:43 PM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
7.5
exploitability
4.4
remediation
7.7
relevance
0.6
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.