CVE-2024-0109

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
31/08/2024
Last modified:
18/09/2024

Description

NVIDIA CUDA Toolkit contains a vulnerability in command `cuobjdump` where a user may cause a crash by passing in a malformed ELF file. A successful exploit of this vulnerability may cause an out of bounds read in the unprivileged process memory which could lead to a limited denial of service.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nvidia:cuda_toolkit:*:*:*:*:*:*:*:* 12.6.0 (including)


References to Advisories, Solutions, and Tools