CVE-2025-23275

NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvJPEG where a local authenticated user may cause a GPU out-of-bounds write by providing certain image dimensions. A successful exploit of this vulnerability may lead to denial of service and information disclosure.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:nvidia:cuda_toolkit:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:nvidia:nvjpeg:-:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:nvidia:driveos:-:*:*:*:*:*:*:*
cpe:2.3:o:nvidia:linux_for_tegra:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-09-24 14:15

Updated : 2025-10-06 14:51


NVD link : CVE-2025-23275

Mitre link : CVE-2025-23275

CVE.ORG link : CVE-2025-23275


JSON object : View

Products Affected

nvidia

  • cuda_toolkit
  • driveos
  • linux_for_tegra
  • nvjpeg

microsoft

  • windows

linux

  • linux_kernel
CWE
CWE-787

Out-of-bounds Write