CVE-2025-23308: NVIDIA Cuda Toolkit
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm where an attacker may cause a heap-based buffer overflow by getting the user to run nvdisasm on a malicious ELF file. A successful exploit of this vulnerability may lead to arbitrary code execution at the privilege level of the user running nvdisasm.
Affected products
- NVIDIA Cuda Toolkit: before 13.0.0 (fixed in 13.0.0)
Published 2025-09-24. Last modified 2026-06-17.