Process crash via unchecked GPU device ordinal
Published Jan 28, 2026 · Updated Jan 28, 2026
Improper GPU device-ID validation in OneFlow 0.9.0 allows remote attackers to crash a GPU-enabled process via a crafted device ID. flow.cuda.get_device_capability passes the supplied ordinal to cudaSetDevice, and an invalid ordinal triggers a fatal check instead of a handled error. Reachability requires an application to expose attacker-controlled device selection, and exploitation aborts that OneFlow process with a core dump.
Summary
What happened
Improper GPU device-ID validation in OneFlow 0.9.0 allows remote attackers to crash a GPU-enabled process via a crafted device ID. flow.cuda.get_device_capability passes the supplied ordinal to cudaSetDevice, and an invalid ordinal triggers a fatal check instead of a handled error. Reachability requires an application to expose attacker-controlled device selection, and exploitation aborts that OneFlow process with a core dump.
The record
- CVE
- CVE-2025-70999
- Published
- Jan 28, 2026
- Updated
- Jan 28, 2026
- Vendor
- Unknown vendor
- Product
- Unknown product
- Classifications
- CWE-400, T1499.004
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- Jan 28, 2026CVE publishedPublication date reported by the CVE source.
- Jan 28, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
What conditions does exploitation require?
What is affected?
Affected products and versions are unavailable in this record.
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
- Invalid device ordinal crash reproducerproof of concept · demonstrated
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo