CVE-2025-23308: NVIDIA Cuda Toolkit

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm where an attacker may cause a heap-based buffer overflow by getting the user to run nvdisasm on a malicious ELF file. A successful exploit of this vulnerability may lead to arbitrary code execution at the privilege level of the user running nvdisasm.

Affected products

  • NVIDIA Cuda Toolkit: before 13.0.0 (fixed in 13.0.0)

Published 2025-09-24. Last modified 2026-06-17.