
Cloud Vulnerability DB
A community-led vulnerabilities database
NVIDIA CUDA toolkit contains a vulnerability (CVE-2024-0072) in cuobjdump and nvdisasm components that affects all platforms. The vulnerability was disclosed in April 2024 and impacts various versions of the CUDA Toolkit prior to the latest security update (NVIDIA Security, ASEC Advisory).
The vulnerability exists in the CUDA toolkit's ability to handle malformed ELF files, specifically within the cuobjdump and nvdisasm components. The severity of this vulnerability has been assessed with a CVSS score of 3.3, indicating a relatively low severity level (ASEC Advisory).
When exploited, this vulnerability can cause a system crash when reading malformed ELF files, potentially leading to denial of service conditions (NVIDIA Security).
The vulnerability can be triggered by tricking a user into processing a specially crafted malformed ELF file through the affected components (NVIDIA Security).
NVIDIA has released patches to address this vulnerability. Users are advised to update to CUDA Toolkit v12.4U1, which contains the security fixes. Additionally, updates are available for related components including nvJPEG2000 v0.7.x and nvTIFF v0.3.0 (ASEC Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."