Nvidia Gpu Operator vulnerabilities

3 known vulnerabilities affecting nvidia/gpu_operator.

Total CVEs
3
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH2LOW1

Vulnerabilities

Page 1 of 1
CVE-2025-23359HIGHCVSS 8.1vAll versions up to and including 24.9.12025-02-12
CVE-2025-23359 [HIGH] CWE-367 CVE-2025-23359: NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where a crafted container image could gain access to the host file system. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and
cvelistv5nvd
CVE-2024-0132HIGHCVSS 8.3PoCvAll versions up to and including 24.6.12024-09-26
CVE-2024-0132 [CRITICAL] CWE-367 CVE-2024-0132: NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerabili NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to code execution, deni
cvelistv5nvd
CVE-2024-0133LOWCVSS 3.4vAll versions up to and including 24.6.12024-09-26
CVE-2024-0133 [MEDIUM] CWE-367 CVE-2024-0133: NVIDIA Container Toolkit 1.16.1 or earlier contains a vulnerability in the default mode of operation NVIDIA Container Toolkit 1.16.1 or earlier contains a vulnerability in the default mode of operation allowing a specially crafted container image to create empty files on the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to data tampering.
cvelistv5nvd