CVE-2025-23275
CUDA Toolkit vulnerability analysis and mitigation

Overview

CVE-2025-23275 is a vulnerability discovered in NVIDIA CUDA Toolkit's nvJPEG component affecting all platforms. The vulnerability was disclosed on September 24, 2025, where a local authenticated user can cause a GPU out-of-bounds write by providing certain image dimensions (NVIDIA Advisory, NVD).

Technical details

The vulnerability is classified as CWE-787 (Out-of-bounds Write) with a CVSS v3.1 base score of 4.2 (Medium) and vector string CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L. The attack requires local access, has high attack complexity, needs low privileges, and requires user interaction (NVIDIA Advisory).

Impact

A successful exploitation of this vulnerability can lead to denial of service and information disclosure. The impact is considered medium severity due to the potential exposure of sensitive information and system disruption (NVIDIA Advisory, NVD).

Mitigation and workarounds

NVIDIA has released security updates to address this vulnerability. Users should upgrade to CUDA Toolkit 13.0 or nvJPEG 13.0.0 for complete remediation. For systems using nvJPEG specifically, updating to version 25.03 will also address this vulnerability (NVIDIA Advisory).

Community reactions

The vulnerability was discovered and reported by Yuhao Zhou from Sichuan University, demonstrating ongoing security research collaboration between academic institutions and NVIDIA (NVIDIA Advisory).

Additional resources


SourceThis report was generated using AI

Related CUDA Toolkit vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-23339HIGH7.8
  • CUDA ToolkitCUDA Toolkit
  • cpe:2.3:a:nvidia:cuda_toolkit
NoYesSep 24, 2025
CVE-2025-23308HIGH7.8
  • CUDA ToolkitCUDA Toolkit
  • cpe:2.3:a:nvidia:cuda_toolkit
NoYesSep 24, 2025
CVE-2025-23338MEDIUM5.5
  • CUDA ToolkitCUDA Toolkit
  • cpe:2.3:a:nvidia:cuda_toolkit
NoYesSep 24, 2025
CVE-2025-23346LOW3.3
  • CUDA ToolkitCUDA Toolkit
  • cpe:2.3:a:nvidia:cuda_toolkit
NoYesSep 24, 2025
CVE-2025-23340LOW3.3
  • CUDA ToolkitCUDA Toolkit
  • cpe:2.3:a:nvidia:cuda_toolkit
NoYesSep 24, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management