CVE-2024-0132
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/09/2024
Last modified:
02/10/2024
Description
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Impact
Base Score 3.x
8.30
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:nvidia:nvidia_container_toolkit:*:*:*:*:*:*:*:* | 1.16.2 (excluding) | |
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* | ||
cpe:2.3:a:nvidia:nvidia_gpu_operator:*:*:*:*:*:*:*:* | 24.6.2 (excluding) | |
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page