Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-33230

Опубликовано: 20 янв. 2026
Источник: redhat
CVSS3: 6.1

Описание

NVIDIA Nsight Systems for Linux contains a vulnerability in the .run installer, where an attacker could cause an OS command injection by supplying a malicious string to the installation path. A successful exploit of this vulnerability might lead to escalation of privileges, code execution, data tampering, denial of service, and information disclosure.

A flaw was found in the NVIDIA Nsight Systems for Linux installer. An attacker could exploit this vulnerability by providing a malicious string as the installation path, leading to an operating system (OS) command injection. A successful exploit could result in escalation of privileges, arbitrary code execution, data tampering, denial of service, and information disclosure.

Отчет

This vulnerability is rated Important as it impacts the NVIDIA Nsight Systems installer. An attacker could achieve OS command injection by providing a malicious installation path during the execution of the installer. This could lead to escalation of privileges and arbitrary code execution on affected systems running NVIDIA Nsight Systems.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10cuda-nsight-systems-13-0Fix deferred
Red Hat Enterprise Linux 10cuda-nsight-systems-13-1Fix deferred
Red Hat Enterprise Linux 10nsight-systems-2025.3.2Fix deferred
Red Hat Enterprise Linux 10nsight-systems-2025.5.2Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2431287nsight-systems: NVIDIA Nsight Systems for Linux: Privilege escalation and code execution via OS command injection in installer

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
7 месяцев назад

NVIDIA Nsight Systems for Linux contains a vulnerability in the .run installer, where an attacker could cause an OS command injection by supplying a malicious string to the installation path. A successful exploit of this vulnerability might lead to escalation of privileges, code execution, data tampering, denial of service, and information disclosure.

CVSS3: 7.3
nvd
7 месяцев назад

NVIDIA Nsight Systems for Linux contains a vulnerability in the .run installer, where an attacker could cause an OS command injection by supplying a malicious string to the installation path. A successful exploit of this vulnerability might lead to escalation of privileges, code execution, data tampering, denial of service, and information disclosure.

CVSS3: 7.3
debian
7 месяцев назад

NVIDIA Nsight Systems for Linux contains a vulnerability in the .run i ...

CVSS3: 7.3
github
7 месяцев назад

NVIDIA Nsight Systems for Linux contains a vulnerability in the .run installer, where an attacker could cause an OS command injection by supplying a malicious string to the installation path. A successful exploit of this vulnerability might lead to escalation of privileges, code execution, data tampering, denial of service, and information disclosure.

CVSS3: 7.3
fstec
7 месяцев назад

Уязвимость инструмента анализа производительности системы NVIDIA NSight Systems программного средства для параллельных вычислений на графических процессорах NVIDIA CUDA Toolkit, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации, повысить свои привилегии, выполнить произвольный код, осуществить подмену данных или вызвать отказ в обслуживании

6.1 Medium

CVSS3