CVE-2025-6603: Coldfunction Qcuda
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
A vulnerability was found in coldfunction qCUDA up to db0085400c2f2011eed46fbc04fdc0873141688e. It has been rated as problematic. Affected by this issue is the function qcow_make_empty of the file qCUDA/qcu-device/block/qcow.c. The manipulation of the argument s->l1_size leads to integer overflow. The attack needs to be approached locally. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
Affected products
- Coldfunction Qcuda
Published 2025-06-25. Last modified 2026-06-17.