CNNVD-202601-3199 Information
CNNVD ID
CNNVD-202601-3199
Related CVE
- CNNVD Published: 2026-01-20
Description (Chinese)
NVIDIA CUDA toolkit是美国英伟达(NVIDIA)公司的一个工具包。为创建高性能 GPU 加速应用程序提供了一个开发环境。 NVIDIA CUDA toolkit存在操作系统命令注入漏洞,该漏洞源于NVIDIA Nsight Systems的gfx_hotspot模块存在缺陷,可能导致OS命令注入,进而导致代码执行、权限提升、数据篡改、拒绝服务和信息泄露。
Description (English)
NVIDIA CUDA toolkit is a toolkit for NVIDIA in the United States. A development environment was provided for the creation of high performance GPU acceleration applications. NVIDIA CUDA toolkit has an operational system command leak, which stems from deficiencies in the gfx hotspot module of NVIDIA Nsight Systems, which may lead to the injection of an OS command, leading to code execution, power enhancement, data manipulation, denial of services and information disclosure.
Hazard Level
Medium
Vulnerability Type
操作系统命令注入
Affected Vendor
英伟达
Published
2026-01-20
Last Modified
2026-02-24
References
https://nvd.nist.gov/vuln/detail/CVE-2025-33228 https://nvidia.custhelp.com/app/answers/detail/a_id/5755 https://www.cve.org/CVERecord?id=CVE-2025-33228
Patch
https://nvidia.custhelp.com/app/answers/detail/a_id/5755
Share on: