CUDA Toolkit Vulnerability Could Lead to Code Execution or Denial of Service
CVE-2024-0110
7.8HIGH
What is CVE-2024-0110?
The NVIDIA CUDA Toolkit exhibits a vulnerability within the cuobjdump
command, specifically when it processes malformed ELF (Executable and Linkable Format) files. This flaw enables users to inadvertently induce an out-of-bound write situation. If exploited, this vulnerability could allow unauthorized code execution or lead to denial of service, impacting system stability and security. Users of the NVIDIA CUDA Toolkit should review their use of the cuobjdump
command and take measures to validate input files to mitigate potential risks.
Affected Version(s)
CUDA Toolkit Windows All versions up to and including CUDA Toolkit 12.6