Nvidia and Adobe vulnerabilities

Nvidia and Adobe vulnerabilities

Cisco Talos’ Vulnerability Discovery & Research team recently disclosed five vulnerabilities in Nvidia and one in Adobe Acrobat.

The vulnerabilities mentioned in this blog post have been patched by their respective vendors, all in adherence to Cisco’s third-party vulnerability disclosure policy.    

For Snort coverage that can detect the exploitation of these vulnerabilities, download the latest rule sets from Snort.org, and our latest Vulnerability Advisories are always posted on Talos Intelligence’s website.     

Nvidia vulnerabilities

Discovered by Dimitrios Tatsis of Cisco Talos.

Nvidia is a large technology company developing graphics cards, chip systems, and applications for AI and high performance computing. Talos has found 5 vulnerabilities in the CUDA Toolkit, a development environment for developing GPU-accelerated applications.

TALOS-2025-2155 (CVE-2025-23339) is an arbitrary code execution vulnerability in the DWARF parsing functionality of NVIDIA cuobjdump 12.8.55. A specially crafted fatbin file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

TALOS-2025-2169 (CVE-2025-23338) is an improper array index validation vulnerability in the symbol table parsing functionality of NVIDIA nvdisasm 12.8.90. A specially crafted ELF file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.

TALOS-2025-2172 (CVE-2025-23340) is an out-of-bounds write vulnerability in the RELA section parsing functionality of NVIDIA nvdisasm 12.8.90. A specially crafted ELF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.

TALOS-2025-2191 (CVE-2025-23271), a heap-based buffer overflow vulnerability, and TALOS-2025-2204 (CVE-2025-23308), an out-of-bounds write vulnerability, exist in the REL section header parsing functionality of NVIDIA nvdisasm 12.8.90. Specially crafted ELF files can lead to arbitrary code execution. An attacker can provide a malicious file to trigger these vulnerabilities.

Adobe use-after-free vulnerability

Discovered by KPC of Cisco Talos.

Adobe Acrobat Reader is one of the most popular PDF reading software currently available.

Talos discovered TALOS-2025-2222 (CVE-2025-54257), a use-after-free vulnerability in the page property functionality of Adobe Acrobat Reader 2025.001.20531. Specially crafted Javascript code inside a malicious PDF document can trigger reuse of a previously freed object, which can lead to memory corruption and could result in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability.

Cisco Talos Blog – ​Read More

This smart garden makes it easy to grow up to 16 plants at home – here’s how

The Gardyn Studio 2.0 is the smartest indoor garden I’ve seen, even featuring a camera that uses AI to assess your plants.

Latest news – ​Read More

Photoshop’s new AI tool made my composite images look real in one click – and now I’m hooked

Photoshop Harmonize automatically adjusts an object’s color, lighting, and shadows to match any background. It’s very, very good.

Latest news – ​Read More

Meet SpamGPT and MatrixPDF, AI Toolkits Driving Malware Attacks

Cybersecurity researchers at Varonis have discovered two new plug-and-play cybercrime toolkits, MatrixPDF and SpamGPT. Learn how these AI-powered tools make mass phishing and PDF malware accessible to anyone, redefining online security risks.

Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto – ​Read More

UK Police Convicts Pair in £5.5 Billion Bitcoin Launder Case

Two defendants pleaded guilty in a Bitcoin laundering case tied to the UK’s record crypto seizure. The Met’s seven-year probe moves to sentencing 10–11 November.

The post UK Police Convicts Pair in £5.5 Billion Bitcoin Launder Case appeared first on TechRepublic.

Security Archives – TechRepublic – ​Read More

I tested the Apple Watch Ultra 3’s satellite connectivity off-grid, and it’s even better than Garmin’s

The Apple Watch Ultra 3 supports satellite connectivity, letting users share their location and send texts miles away from network coverage.

Latest news – ​Read More

This fundamental Android feature is ‘absolutely not’ going away, says Google – but it is changing

Google says these changes are meant to protect you.

Latest news – ​Read More

OpenSSL Vulnerabilities Allow Private Key Recovery, Code Execution, DoS Attacks

Three vulnerabilities have been patched with the release of OpenSSL updates. 

The post OpenSSL Vulnerabilities Allow Private Key Recovery, Code Execution, DoS Attacks appeared first on SecurityWeek.

SecurityWeek – ​Read More

Final 3 days to score extra discounts on community passes to TechCrunch Disrupt 2025

Only 3 days left to lock in even bigger savings on group passes to TechCrunch Disrupt 2025! Exclusive to founders and investors, save up to 20% on groups of 4–9 until Friday, October 3 at 11:59 p.m. PT.

Security News | TechCrunch – ​Read More

Google’s ‘Gemini for Home’ upgrade is coming – and it’ll work with older Nest devices

Some of the AI updates coming to Google Home will require a subscription.

Latest news – ​Read More