cbcvebase.

Github.Com Nvidia Nvidia-Container-Toolkit vulnerabilities

4 known vulnerabilities affecting github.com/nvidia_nvidia-container-toolkit.

Total CVEs
4
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH1MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2024-0132P2CRITICALPoC≥ 0, < 1.16.22024-10-29
CVE-2024-0132 [CRITICAL] CWE-367 NVIDIA Container Toolkit contains a Time-of-check Time-of-Use (TOCTOU) vulnerability NVIDIA Container Toolkit contains a Time-of-check Time-of-Use (TOCTOU) vulnerability NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use cases where CDI is used. A successful exploit
ghsaosv
CVE-2025-23266P3CRITICAL≥ 0, < 1.17.82025-07-17
CVE-2025-23266 [CRITICAL] CWE-426 NVIDIA Container Toolkit for all platforms contains an Untrusted Search Path NVIDIA Container Toolkit for all platforms contains an Untrusted Search Path NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure
ghsaosv
CVE-2025-23267P3HIGH≥ 0, < 1.17.82025-07-17
CVE-2025-23267 [HIGH] CWE-59 NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook, where an attacker could cause a link following by using a specially crafted container image. A successful exploit of this vulnerability might lead to data tampering and denial of servi
ghsaosv
CVE-2024-0133P4MEDIUM≥ 0, < 1.16.22024-10-29
CVE-2024-0133 [MEDIUM] CWE-367 NVIDIA Container Toolkit allows specially crafted container image to create empty files on the host file system NVIDIA Container Toolkit allows specially crafted container image to create empty files on the host file system NVIDIA Container Toolkit 1.16.1 or earlier contains a vulnerability in the default mode of operation allowing a specially crafted container image to create empty files on the host file system. This does not impact use cases where CDI is used. A
ghsaosv
Github.Com Nvidia Nvidia-Container-Toolkit vulnerabilities | cvebase