
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-23275 is a vulnerability discovered in NVIDIA CUDA Toolkit's nvJPEG component affecting all platforms. The vulnerability was disclosed on September 24, 2025, where a local authenticated user can cause a GPU out-of-bounds write by providing certain image dimensions (NVIDIA Advisory, NVD).
The vulnerability is classified as CWE-787 (Out-of-bounds Write) with a CVSS v3.1 base score of 4.2 (Medium) and vector string CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L. The attack requires local access, has high attack complexity, needs low privileges, and requires user interaction (NVIDIA Advisory).
A successful exploitation of this vulnerability can lead to denial of service and information disclosure. The impact is considered medium severity due to the potential exposure of sensitive information and system disruption (NVIDIA Advisory, NVD).
NVIDIA has released security updates to address this vulnerability. Users should upgrade to CUDA Toolkit 13.0 or nvJPEG 13.0.0 for complete remediation. For systems using nvJPEG specifically, updating to version 25.03 will also address this vulnerability (NVIDIA Advisory).
The vulnerability was discovered and reported by Yuhao Zhou from Sichuan University, demonstrating ongoing security research collaboration between academic institutions and NVIDIA (NVIDIA Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."