Your message dated Sun, 12 May 2024 22:07:20 +0000
with message-id <[email protected]>
and subject line Bug#1034793: fixed in nvidia-cuda-toolkit 12.1.1-1
has caused the Debian Bug report #1034793,
regarding nvidia-cuda-toolkit: CVE-2023-25510, CVE-2023-25511, CVE-2023-25514
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1034793: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1034793
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: nvidia-cuda-toolkit
Version: 4.0.13-1
Severity: important
Tags: security
https://nvidia.custhelp.com/app/answers/detail/a_id/5456
CVE-2023-25512 NVIDIA CUDA toolkit for Linux and Windows contains a
vulnerability in cuobjdump, where an attacker may cause an out-of-bounds
memory read by running cuobjdump on a malformed input file. A successful
exploit of this vulnerability may lead to limited denial of service,
code execution, and limited information disclosure.
CVE-2023-25513 NVIDIA CUDA toolkit for Linux and Windows contains a
vulnerability in cuobjdump, where an attacker may cause an out-of-bounds
read by tricking a user into running cuobjdump on a malformed input
file. A successful exploit of this vulnerability may lead to limited
denial of service, code execution, and limited information disclosure.
CVE-2023-25514 NVIDIA CUDA toolkit for Linux and Windows contains a
vulnerability in cuobjdump, where an attacker may cause an out-of-bounds
read by tricking a user into running cuobjdump on a malformed input
file. A successful exploit of this vulnerability may lead to limited
denial of service, code execution, and limited information disclosure.
CVE-2023-25510 NVIDIA CUDA Toolkit SDK for Linux and Windows contains a
NULL pointer dereference in cuobjdump, where a local user running the
tool against a malformed binary may cause a limited denial of service.
CVE-2023-25511 NVIDIA CUDA Toolkit for Linux and Windows contains a
vulnerability in cuobjdump, where a division-by-zero error may enable a
user to cause a crash, which may lead to a limited denial of service.
CVEs Addressed Affected Versions Updated Version
CVE-2023-25510
CVE-2023-25511
CVE-2023-25514 All versions prior to 12.1 Update 1 12.1 Update 1
CVE-2023-25512 All versions prior to 12.1 12.1
CVE-2023-25513 All versions prior to 12.0 Update 1 12.0 Update 1
Andreas
--- End Message ---
--- Begin Message ---
Source: nvidia-cuda-toolkit
Source-Version: 12.1.1-1
Done: Andreas Beckmann <[email protected]>
We believe that the bug you reported is fixed in the latest version of
nvidia-cuda-toolkit, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Andreas Beckmann <[email protected]> (supplier of updated nvidia-cuda-toolkit
package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Format: 1.8
Date: Sun, 12 May 2024 21:57:53 +0200
Source: nvidia-cuda-toolkit
Architecture: source
Version: 12.1.1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian NVIDIA Maintainers <[email protected]>
Changed-By: Andreas Beckmann <[email protected]>
Closes: 1034793
Changes:
nvidia-cuda-toolkit (12.1.1-1) unstable; urgency=medium
.
* New upstream release 12.1.1 (April 2023).
* Fixes CVE-2023-25510, CVE-2023-25511, CVE-2023-25514. (Closes: #1034793)
https://nvidia.custhelp.com/app/answers/detail/a_id/5456
* Refresh patches.
Checksums-Sha1:
b8aa59a982867fbf1c72eef80260e48236d345cc 9748 nvidia-cuda-toolkit_12.1.1-1.dsc
ee9035b200a08d17aa1535079f26d9e906450d23 2409596412
nvidia-cuda-toolkit_12.1.1.orig-amd64.tar.xz
b335c8daf9d4296435d3f56600a47db849567d25 1771184516
nvidia-cuda-toolkit_12.1.1.orig-arm64.tar.xz
5164c86ef63b3f31e287dfd5678acaa5e7651e40 28384300
nvidia-cuda-toolkit_12.1.1.orig-openjdk-8-jre-amd64-8u412-ga-1.tar.xz
2bd691752f6fb287025a0153236465c478bfd95a 28170652
nvidia-cuda-toolkit_12.1.1.orig-openjdk-8-jre-ppc64el-8u412-ga-1.tar.xz
0067307f2370915686807b86869b63ae75b5d90c 67052932
nvidia-cuda-toolkit_12.1.1.orig-openjdk-8-source-8u412-ga-1.tar.xz
d4192b0e1b68139b5d8a3213aaf9aba11f365dfd 1684074436
nvidia-cuda-toolkit_12.1.1.orig-ppc64el.tar.xz
f3aa538f47b347493de0d5bd5bcc98d400490c66 192
nvidia-cuda-toolkit_12.1.1.orig.tar.xz
fffc5fdc133305a4d44d16b837a24ceb05e287f2 68860
nvidia-cuda-toolkit_12.1.1-1.debian.tar.xz
78e824458cec194d36b40647b9fd43a2b41eebca 5757
nvidia-cuda-toolkit_12.1.1-1_source.buildinfo
Checksums-Sha256:
45b67559ea6dc1155dd1cef4b29017452bdcd8139d794225294d83e5d6138426 9748
nvidia-cuda-toolkit_12.1.1-1.dsc
9025bcfa8452fd936585f45ef8abe0ca1257ccd96291e7c589c3419e93902d7e 2409596412
nvidia-cuda-toolkit_12.1.1.orig-amd64.tar.xz
7ced5825c512a9e79757f08b48d79fc2e231b4bae9eea904aa573c2e94314468 1771184516
nvidia-cuda-toolkit_12.1.1.orig-arm64.tar.xz
db865a05cf0997edbd4955df97e4c178d7a4dbee4a77106939a19e1b1aa153df 28384300
nvidia-cuda-toolkit_12.1.1.orig-openjdk-8-jre-amd64-8u412-ga-1.tar.xz
a3d9f277a881b37dc6d15bd9f6e8acd92ddf3b4dab79a1ba85dbc5dfb2585ced 28170652
nvidia-cuda-toolkit_12.1.1.orig-openjdk-8-jre-ppc64el-8u412-ga-1.tar.xz
970c28c6b6788d8bbdae27ec0828bf281c756b1d556cd76165d9873fe9b139fe 67052932
nvidia-cuda-toolkit_12.1.1.orig-openjdk-8-source-8u412-ga-1.tar.xz
8ecd426be5dcecfedad831200866bdafa925809d557fde726ee892e5c25855e7 1684074436
nvidia-cuda-toolkit_12.1.1.orig-ppc64el.tar.xz
81fbc046f66f1f3d0d791b0e4379ed9bac9af98e65f77853ab5bbcf6f332bccf 192
nvidia-cuda-toolkit_12.1.1.orig.tar.xz
82b36dc48f3b75e25b630542cb982f8eaa97de939907e6e1c7145c6a52fa520d 68860
nvidia-cuda-toolkit_12.1.1-1.debian.tar.xz
9e7b2da77ea943211a8b27518c3ecb555ad67943847269ee070036cb1431fd04 5757
nvidia-cuda-toolkit_12.1.1-1_source.buildinfo
Files:
a0b5dbc7b11cd1e47b5fb36692a55ce7 9748 non-free/libs optional
nvidia-cuda-toolkit_12.1.1-1.dsc
65850ba0af833b10a299ca498edd2ba0 2409596412 non-free/libs optional
nvidia-cuda-toolkit_12.1.1.orig-amd64.tar.xz
d9e9eee2389453b6f82ddf55e1f22846 1771184516 non-free/libs optional
nvidia-cuda-toolkit_12.1.1.orig-arm64.tar.xz
0b1a98edba24aebb16ad6d10589c7945 28384300 non-free/libs optional
nvidia-cuda-toolkit_12.1.1.orig-openjdk-8-jre-amd64-8u412-ga-1.tar.xz
b5496cbf2742c8d7b11224d51bc134f2 28170652 non-free/libs optional
nvidia-cuda-toolkit_12.1.1.orig-openjdk-8-jre-ppc64el-8u412-ga-1.tar.xz
3b9597b1a446af0afecafe0b9caf5eb2 67052932 non-free/libs optional
nvidia-cuda-toolkit_12.1.1.orig-openjdk-8-source-8u412-ga-1.tar.xz
7462ecaf843b0d1d8a82293c10eb4e84 1684074436 non-free/libs optional
nvidia-cuda-toolkit_12.1.1.orig-ppc64el.tar.xz
57652bccd1efc15183fc1764e2a225d5 192 non-free/libs optional
nvidia-cuda-toolkit_12.1.1.orig.tar.xz
c10a8cd0b0813abcf1e7f11b171cb575 68860 non-free/libs optional
nvidia-cuda-toolkit_12.1.1-1.debian.tar.xz
f54bf336e7de76aa343bdd823477b75b 5757 non-free/libs optional
nvidia-cuda-toolkit_12.1.1-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJEBAEBCAAuFiEE6/MKMKjZxjvaRMaUX7M/k1np7QgFAmZBLoIQHGFuYmVAZGVi
aWFuLm9yZwAKCRBfsz+TWentCLctEACiFYBtPJnIMGd3gMkRXlFEm2WaUfROT9bY
zvlojxHuN4eu1j3KhKuBLB1oJjuiQ37yzm0+9d5AAzpTJbYJVrSc/PF/MgujNiG/
caDuAhdM7QgD+Eyox2EI0Se5Nkczzy9LdGfvIh3WwHHrfqPTbx7w9nvXLUIQQcMU
IEMoM5Co/wiud3l3xiupd72v7HeuGFwmA1zstjJKJiO4TbcDjTl6gjb/DWv9SM9p
Mn16k4km09u/k+r0PlzkWHxCnT14+ydtKq+FIh5rXmRQn3A6fFNCtNCta2ZaGeBX
AEp6LteiHJ+2j64F1oUE3R7AJXrQLW3rA3mE4f2Oc9A9xcMyPgYPSOLJr/HK6hdB
JVtvd+Ubkrb4v7vL+YTzgIczTY436xvMEeqOT6kOt5MNSFJFYC9g8FXCBPsvP8nn
7ruK+LwnISINRxM5atJtiUMFtaa9U2QMrtBuzOdHVnu+CXnCgM/bmFeChyoh1pS8
C64snomeQnPJy5T47NSoD/x+94KCwiti34v2/1+xEXhjR5tdlxij3Ll8LPm63Eff
AWtHa12gSoApJhhoM5M2HxEQdgt3Id+900czbwKzGaA/bj5ShnOxW14Jv5UcuLRr
xVdzD5pBgPTpxtw+B2xzYkkke/GY5dE/dozKV6ngqH6TvcuDuf/vJexnnDuxQdsv
iKVmzoF2PQ==
=ZdQq
-----END PGP SIGNATURE-----
pgpeJJO6a2GFL.pgp
Description: PGP signature
--- End Message ---