Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-23274

CVSS 4.5 · Medium EPSS 0.02% · P5
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-23274

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
NVIDIA nvJPEG contains a vulnerability in jpeg encoding where a user may cause an out-of-bounds read by providing a maliciously crafted input image with dimensions that cause integer overflows in array index calculations. A successful exploit of this vulnerability may lead to denial of service.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
Source: NVD (National Vulnerability Database)
Vulnerability Type
跨界内存读
Source: NVD (National Vulnerability Database)
Vulnerability Title
NVIDIA CUDA toolkit和NVIDIA nvJPEG 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
NVIDIA CUDA toolkit和NVIDIA nvJPEG都是美国英伟达(NVIDIA)公司的产品。NVIDIA CUDA toolkit是一个工具包。为创建高性能 GPU 加速应用程序提供了一个开发环境。NVIDIA nvJPEG是一个图像编解码库。 NVIDIA CUDA toolkit和NVIDIA nvJPEG存在缓冲区错误漏洞,该漏洞源于处理恶意特制图像时数组索引计算存在整数溢出,可能导致越界读取和拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
NVIDIANVIDIA CUDA Toolkit All versions prior to CUDA Toolkit 13.0 -
NVIDIAnvJPEG All versions prior to nvJPEG 13.0.0 -

II. Public POCs for CVE-2025-23274

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-23274

登录查看更多情报信息。

Same Patch Batch · NVIDIA · 2025-09-24 · 16 CVEs total

CVE-2025-233547.8 HIGHNVIDIA Megatron-LM 代码注入漏洞
CVE-2025-233537.8 HIGHNVIDIA Megatron-LM 代码注入漏洞
CVE-2025-233497.8 HIGHNVIDIA Megatron-LM 代码注入漏洞
CVE-2025-233487.8 HIGHNVIDIA Megatron-LM 代码注入漏洞
CVE-2025-232725.7 MEDIUMNVIDIA CUDA toolkit和NVIDIA nvJPEG 缓冲区错误漏洞
CVE-2025-232754.2 MEDIUMNVIDIA CUDA Toolkit 缓冲区错误漏洞
CVE-2025-233463.3 LOWNVIDIA CUDA Toolkit 代码问题漏洞
CVE-2025-233403.3 LOWNVIDIA CUDA Toolkit 缓冲区错误漏洞
CVE-2025-233393.3 LOWNVIDIA CUDA Toolkit 安全漏洞
CVE-2025-233383.3 LOWNVIDIA CUDA Toolkit 输入验证错误漏洞
CVE-2025-233083.3 LOWNVIDIA CUDA Toolkit 安全漏洞
CVE-2025-232713.3 LOWNVIDIA CUDA Toolkit 缓冲区错误漏洞
CVE-2025-232553.3 LOWNVIDIA CUDA Toolkit 缓冲区错误漏洞
CVE-2025-232483.3 LOWNVIDIA CUDA Toolkit 缓冲区错误漏洞
CVE-2025-232732.5 LOWNVIDIA CUDA Toolkit 数字错误漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2025-23274

No comments yet


Leave a comment