Nvidia Container Toolkit vulnerabilities
7 known vulnerabilities affecting nvidia/nvidia_container_toolkit.
Total CVEs
7
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM2LOW1
Vulnerabilities
Page 1 of 1
CVE-2025-23359HIGHCVSS 8.1fixed in 1.17.42025-02-12
CVE-2025-23359 [HIGH] CWE-367 CVE-2025-23359: NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when
NVIDIA Container Toolkit for Linux contains a Time-of-Check Time-of-Use (TOCTOU) vulnerability when used with default configuration, where a crafted container image could gain access to the host file system. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and
nvd
CVE-2024-0135HIGHCVSS 7.6fixed in 1.17.3vAll versions up to and including v1.17.02025-01-28
CVE-2024-0135 [HIGH] CWE-653 CVE-2024-0135: NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted cont
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to modification of a host binary. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
cvelistv5nvd
CVE-2024-0136HIGHCVSS 8.4fixed in 1.17.3vAll versions up to and including v1.17.02025-01-28
CVE-2024-0136 [HIGH] CWE-653 CVE-2024-0136: NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted cont
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code obtaining read and write access to host devices. This vulnerability is present only when the NVIDIA Container Toolkit is configured in a nondefault way. A successful exploit of this vulnerability may lead to code e
cvelistv5nvd
CVE-2024-0137MEDIUMCVSS 6.5fixed in 1.17.3vAll versions up to and including v1.17.02025-01-28
CVE-2024-0137 [MEDIUM] CWE-653 CVE-2024-0137: NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted cont
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code running in the host’s network namespace. This vulnerability is present only when the NVIDIA Container Toolkit is configured in a nondefault way. A successful exploit of this vulnerability may lead to denial of se
cvelistv5nvd
CVE-2024-0134MEDIUMCVSS 4.1fixed in 1.17vAll versions up to and including v1.16.22024-11-05
CVE-2024-0134 [MEDIUM] CWE-61 CVE-2024-0134: NVIDIA Container Toolkit and NVIDIA GPU Operator for Linux contain a UNIX vulnerability where a spec
NVIDIA Container Toolkit and NVIDIA GPU Operator for Linux contain a UNIX vulnerability where a specially crafted container image can lead to the creation of unauthorized files on the host. The name and location of the files cannot be controlled by an attacker. A successful exploit of this vulnerability might lead to data tampering.
cvelistv5nvd
CVE-2024-0132HIGHCVSS 8.3PoCfixed in 1.16.22024-09-26
CVE-2024-0132 [CRITICAL] CWE-367 CVE-2024-0132: NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerabili
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to code execution, deni
nvd
CVE-2024-0133LOWCVSS 3.4fixed in 1.16.22024-09-26
CVE-2024-0133 [MEDIUM] CWE-367 CVE-2024-0133: NVIDIA Container Toolkit 1.16.1 or earlier contains a vulnerability in the default mode of operation
NVIDIA Container Toolkit 1.16.1 or earlier contains a vulnerability in the default mode of operation allowing a specially crafted container image to create empty files on the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to data tampering.
nvd