
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-23275 is an out-of-bounds write vulnerability in the nvJPEG component of NVIDIA CUDA Toolkit affecting all platforms. A local authenticated user can trigger a GPU out-of-bounds write by supplying specially crafted image dimensions, potentially leading to denial of service and information disclosure. The vulnerability affects all versions of NVIDIA CUDA Toolkit prior to 13.0.0 and the standalone nvJPEG library. It was published on September 24, 2025, with NVD initial analysis completed on October 6, 2025. NVD assigns a CVSS v3.1 base score of 7.1 (High), while NVIDIA's own CNA assessment rates it 4.2 (Medium) (NVIDIA Advisory, Red Hat CVE).
The root cause is classified as CWE-787 (Out-of-bounds Write), where the nvJPEG library fails to properly validate image dimension parameters before performing GPU memory write operations. An attacker provides a crafted image with specific dimensions that cause the library to write beyond the bounds of an allocated GPU memory buffer. Exploitation requires local authenticated access with low privileges and no user interaction (per NVD's assessment), though NVIDIA's own vector indicates high attack complexity and requires user interaction. The affected component, nvJPEG, is a GPU-accelerated JPEG decoder included in the CUDA Toolkit and also distributed as a standalone library (NVIDIA Advisory, Red Hat CVE).
Successful exploitation can result in denial of service by crashing or destabilizing the GPU, as well as information disclosure through exposure of GPU memory contents that may contain sensitive data from other processes. The vulnerability's scope is limited to the local system (unchanged scope), meaning it does not directly enable lateral movement across a network. Systems using nvJPEG for image processing workloads — including AI/ML pipelines, media processing servers, and scientific computing environments — are at risk of service disruption and potential leakage of GPU-resident data (NVIDIA Advisory, Red Hat CVE).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time. The EPSS score is extremely low at approximately 0.012%, reflecting a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection plugins are available via Nessus (plugin 265968) and Qualys (detection ID 361113) (Feedly, Tenable).
NVIDIA has released a fix in CUDA Toolkit version 13.0.0; users should upgrade to this version or later to remediate the vulnerability. As interim mitigations, organizations should restrict local user access to systems running CUDA Toolkit, implement strict input validation for image processing workflows that use nvJPEG, and monitor for unusual GPU behavior or performance degradation. The nvJPEG standalone library should also be updated to version 13.0.0 or newer where applicable (NVIDIA Advisory).
NVIDIA disclosed this vulnerability as part of its September 2025 CUDA Toolkit security bulletin. Red Hat has tracked the CVE for potential impact on its products. No notable independent researcher commentary or significant social media discussion has been identified for this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."