7.1
CVE-2025-23275
- EPSS 0.02%
- Published 24.09.2025 14:15:47
- Last modified 06.10.2025 14:51:06
- Source psirt@nvidia.com
- Teams watchlist Login
- Open Login
NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvJPEG where a local authenticated user may cause a GPU out-of-bounds write by providing certain image dimensions. A successful exploit of this vulnerability may lead to denial of service and information disclosure.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users. Login
Data is provided by the National Vulnerability Database (NVD)
Nvidia ≫ Cuda Toolkit Version < 13.0.0
Nvidia ≫ Nvjpeg Version-
Linux ≫ Linux Kernel Version-
Microsoft ≫ Windows Version-
Nvidia ≫ Driveos Version-
Nvidia ≫ Linux For Tegra Version-
Microsoft ≫ Windows Version-
Nvidia ≫ Driveos Version-
Nvidia ≫ Linux For Tegra Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.02% | 0.021 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.1 | 1.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
|
psirt@nvidia.com | 4.2 | 0.8 | 3.4 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.