CVE-2025-23346
CUDA Toolkit vulnerability analysis and mitigation

Overview

CVE-2025-23346 is a NULL pointer dereference vulnerability in the cuobjdump utility of the NVIDIA CUDA Toolkit, allowing an unprivileged local user to trigger a limited denial of service. It affects all CUDA Toolkit versions prior to 13.0.0 on both Windows and Linux platforms. The vulnerability was disclosed by NVIDIA Corporation on September 24, 2025, with NVD initial analysis completed on October 6, 2025. It carries a CVSS v3.1 base score of 3.3 (Low), assigned by NVIDIA (NVIDIA Advisory, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-476 (NULL Pointer Dereference) and resides in the cuobjdump command-line utility included with the NVIDIA CUDA Toolkit. An unprivileged user can supply a crafted input to cuobjdump that causes the application to dereference a NULL pointer, resulting in a crash. Exploitation requires local access and user interaction (e.g., a user running cuobjdump against a malicious file), and no elevated privileges are needed. No public proof-of-concept or detailed technical write-up has been identified (NVIDIA Advisory, Red Hat CVE).

Impact

Successful exploitation results in a limited denial of service — specifically, a crash of the cuobjdump process. There is no impact on confidentiality or integrity, and the availability impact is confined to the affected utility rather than the broader system or GPU workloads. The vulnerability does not enable code execution, privilege escalation, or lateral movement, making its overall risk low (NVIDIA Advisory, Red Hat CVE).

Mitigation and workarounds

NVIDIA has released CUDA Toolkit version 13.0.0 as the fix for this vulnerability; users should upgrade to version 13.0.0 or later. As interim mitigations, organizations should limit local user access to systems running the CUDA Toolkit, apply least-privilege principles to restrict who can execute cuobjdump, and monitor for unexpected crashes of the utility. No configuration-based workaround has been published by NVIDIA (NVIDIA Advisory).

Additional resources


SourceThis report was generated using AI

Related CUDA Toolkit vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-33230HIGH7.3
  • CUDA Toolkit logoCUDA Toolkit
  • nsight-systems-2025.5.2
NoYesJan 20, 2026
CVE-2025-33229HIGH7.3
  • CUDA Toolkit logoCUDA Toolkit
  • cuda-nsight-systems-13-0
NoYesJan 20, 2026
CVE-2025-33228HIGH7.3
  • CUDA Toolkit logoCUDA Toolkit
  • cpe:2.3:a:nvidia:cuda_toolkit
NoYesJan 20, 2026
CVE-2025-33231MEDIUM6.7
  • CUDA Toolkit logoCUDA Toolkit
  • cpe:2.3:a:nvidia:cuda_toolkit
NoYesJan 20, 2026
CVE-2025-23346LOW3.3
  • CUDA Toolkit logoCUDA Toolkit
  • cuda-cuobjdump-12-6
NoYesSep 24, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management