NVIDIA CUDA Toolkit cuobjdump Stack-Based Buffer Overflow Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A stack-based buffer overflow vulnerability has been identified in the NVIDIA CUDA Toolkit cuobjdump component, present in all versions prior to CUDA Toolkit 13.0. This vulnerability allows an attacker to execute arbitrary code at the privilege level of the user running cuobjdump, by manipulating the user to process a malicious ELF file. The issue arises from improper handling of the file, leading to the potential for exploitation.

Impact

Exploitation of this vulnerability could result in arbitrary code execution, with the executed code running at the same privilege level as the user who invoked cuobjdump.

Remediation

Users are advised to upgrade to NVIDIA CUDA Toolkit 13.0 or later. The latest version can be downloaded from the CUDA Toolkit Downloads page.

Added: Sep 24, 2025, 2:24 PM
Updated: Sep 24, 2025, 9:42 PM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
7.5
exploitability
4.4
remediation
7.7
relevance
0.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.