---
id: CVE-2025-23339
title: >-
  NVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump
  where an attacker may cause a stack-based buffer overflow by getting the user
  to run cuobjdump on a malicious ELF file
summary: >-
  NVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump
  where an attacker may cause a stack-based buffer overflow by getting the user
  to run cuobjdump on a malicious ELF file. A successful exploit of this
  vulnerabilit…
severity: low
cvss: 3.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'
cwe:
  - CWE-121
vendor: nvidia
product: cuda_toolkit
affected:
  - cuda_toolkit < 13.0.0
patched:
  - cuda_toolkit 13.0.0
published: '2025-09-24'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T00:10:00.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-23339'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-23339'
    label: psirt@nvidia.com
  - url: 'https://nvidia.custhelp.com/app/answers/detail/a_id/5661'
    label: psirt@nvidia.com
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-23339'
    label: psirt@nvidia.com
  - url: 'https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2155'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.00363
epssPercentile: 0.27453
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/SpiralBL0CK/ce-for-CVE-2025-23339'
  checkedAt: '2026-09-26T00:23:14.508Z'
exploitAvailable: true
ingestedAt: '2026-09-26T00:22:39.952Z'
---

## Overview

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in cuobjdump where an attacker may cause a stack-based buffer overflow by getting the user to run cuobjdump on a malicious ELF file. A successful exploit of this vulnerability may lead to arbitrary code execution at the privilege level of the user running 
cuobjdump.

## Affected

- `cuda_toolkit < 13.0.0`

## Remediation

Upgrade past the affected range:

- `cuda_toolkit 13.0.0`
