
Cloud Vulnerability DB
A community-led vulnerabilities database
NVIDIA CUDA Toolkit SDK contains a bug in cuobjdump, where a local user running the tool against an ill-formed binary may cause a null-pointer dereference, which may result in a limited denial of service. This vulnerability was disclosed on March 1, 2023, and affects all versions of NVIDIA CUDA Toolkit prior to version 12.1 on both Linux and Windows operating systems (NVIDIA Bulletin).
The vulnerability has been assigned CVE-2023-0196 with a CVSS v3.1 base score of 3.3 (AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L) and is categorized under CWE-476 (NULL Pointer Dereference). The vulnerability specifically affects the cuobjdump tool within the CUDA Toolkit SDK (NVIDIA Bulletin).
When exploited, this vulnerability can result in a limited denial of service through a null-pointer dereference when processing malformed binaries. The impact is considered relatively low as indicated by its CVSS score of 3.3 (NVIDIA Bulletin).
NVIDIA has released version 12.1 of the CUDA Toolkit to address this vulnerability. Users are advised to upgrade to this version or later to mitigate the security risk. The update is available through the CUDA Toolkit Downloads page (NVIDIA Bulletin).
The vulnerability was reported by security researcher hjy79425575, who was acknowledged by NVIDIA for their contribution to discovering this security issue (NVIDIA Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."