Out-of-Bounds Read Vulnerability in NVIDIA CUDA Toolkit
CVE-2025-23255

3.3LOW

Key Information:

Vendor

Nvidia

Vendor
CVE Published:
24 September 2025

What is CVE-2025-23255?

The NVIDIA CUDA Toolkit is vulnerable due to a flaw in the cuobjdump binary. An attacker may exploit this vulnerability by supplying a carefully crafted ELF file, leading to an out-of-bounds read condition. This could result in unexpected behavior, including potential disruptions to service availability, posing risks to system integrity and performance. Users of the CUDA Toolkit are advised to review their current implementations and apply the necessary measures to mitigate the impact of this vulnerability.

Affected Version(s)

NVIDIA CUDA Toolkit Windows All versions prior to CUDA Toolkit 13.0

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-23255 : Out-of-Bounds Read Vulnerability in NVIDIA CUDA Toolkit