cbcvebase.
CVE-2024-0132
published 2024-09-26

CVE-2024-0132: NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a…

high8.3CVSS 3.1
AVNACHPRNUIRSCCHIHAH
EXPLOIT
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

Affected

11 ranges
VendorProductVersion rangeFixed in
github.comnvidia_nvidia-container-toolkit>= 0 < 1.16.21.16.2
msrcazure_kubernetes_service_node_on_azure_linux
msrcazure_kubernetes_service_node_on_ubuntu_linux
msrcazure_linux_3.0_arm
msrcazure_linux_3.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
nvidiacontainer_toolkit
nvidiagpu_operator
nvidianvidia_container_toolkit< 1.16.21.16.2
nvidianvidia_gpu_operator< 24.6.224.6.2