NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code obtaining read and write access to host devices. This vulnerability is present only when the NVIDIA Container Toolkit is configured in a nondefault way. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
References
| Link | Resource |
|---|---|
| https://nvidia.custhelp.com/app/answers/detail/a_id/5599 | Vendor Advisory Mitigation |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2025-01-28 03:15
Updated : 2025-10-06 14:07
NVD link : CVE-2024-0136
Mitre link : CVE-2024-0136
CVE.ORG link : CVE-2024-0136
JSON object : View
Products Affected
nvidia
- nvidia_gpu_operator
- nvidia_container_toolkit
linux
- linux_kernel
CWE
CWE-653
Improper Isolation or Compartmentalization
