[Git][security-tracker-team/security-tracker][master] Add new set of nvidia-cuda-toolkit CVEs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Jan 20 21:12:14 GMT 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
9d4dc9bd by Salvatore Bonaccorso at 2026-01-20T22:10:15+01:00
Add new set of nvidia-cuda-toolkit CVEs

While the description mixes NVIDIA Nsight Systems individually for
Windows and Linux systems, the security updates section of the advisory
lists all of CVE-2025-33228, CVE-2025-33229, CVE-2025-33230 and
CVE-2025-33231 for NVIDIA CUDA Toolkit all versions up to CUDA Toolkit
13.1.

So for now at least consider those CVEs for nvidia-cuda-toolkit until
further clarified.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -161,13 +161,17 @@ CVE-2025-36058 (IBM Business Automation Workflow containers 25.0.0 through 25.0.
 CVE-2025-33233 (NVIDIA Merlin Transformers4Rec for all platforms contains a vulnerabil ...)
 	NOT-FOR-US: NVIDIA
 CVE-2025-33231 (NVIDIA Nsight Systems for Windows contains a vulnerability in the appl ...)
-	TODO: check
+	- nvidia-cuda-toolkit <unfixed>
+	NOTE: https://nvidia.custhelp.com/app/answers/detail/a_id/5755
 CVE-2025-33230 (NVIDIA Nsight Systems for Linux contains a vulnerability in the .run i ...)
-	TODO: check
+	- nvidia-cuda-toolkit <unfixed>
+	NOTE: https://nvidia.custhelp.com/app/answers/detail/a_id/5755
 CVE-2025-33229 (NVIDIA Nsight Visual Studio for Windows contains a vulnerability in Ns ...)
-	TODO: check
+	- nvidia-cuda-toolkit <unfixed>
+	NOTE: https://nvidia.custhelp.com/app/answers/detail/a_id/5755
 CVE-2025-33228 (NVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot reci ...)
-	TODO: check
+	- nvidia-cuda-toolkit <unfixed>
+	NOTE: https://nvidia.custhelp.com/app/answers/detail/a_id/5755
 CVE-2025-33015 (IBM Concert 1.0.0 through 2.1.0 is vulnerable to malicious file upload ...)
 	NOT-FOR-US: IBM
 CVE-2025-1722 (IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtai ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9d4dc9bdb0b663e693dc6eb6c039318dac48b9e9

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9d4dc9bdb0b663e693dc6eb6c039318dac48b9e9
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260120/5bced4ea/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list