NVIDIA CUDA toolkit for all platforms contains a vulnerability in the cuobjdump binary, where a user could cause an out-of-bounds read by passing a malformed ELF file to cuobjdump. A successful exploit of this vulnerability might lead to a partial denial of service.
CVE ID: CVE-2024-53874
CVSS Base Severity: LOW
CVSS Base Score: 3.3
CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Vendor: NVIDIA
Product: CUDA Toolkit
EPSS Score: 0.02% (probability of being exploited)
EPSS Percentile: 2.89% (scored less or equal to compared to others)
EPSS Date: 2025-03-26 (when was this score calculated)
SSVC Exploitation: none
SSVC Technical Impact: partial
SSVC Automatable: false