NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvJPEG where a local authenticated user may cause a GPU out-of-bounds write by providing certain image dimensions. A successful exploit of this vulnerability may lead to denial of service and information disclosure.
2025-09-24T14:15:47.660
2025-10-06T14:51:06.530
Analyzed
CVSSv3.1: 4.2 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | nvidia | cuda_toolkit | < 13.0.0 | Yes |
| Operating System | linux | linux_kernel | - | No |
| Operating System | microsoft | windows | - | No |
| Application | nvidia | nvjpeg | - | Yes |
| Operating System | linux | linux_kernel | - | No |
| Operating System | microsoft | windows | - | No |
| Operating System | nvidia | driveos | - | No |
| Operating System | nvidia | linux_for_tegra | - | No |