PT-2023-9664 · Nvidia+2 · Nvidia Container Toolkit+2

Andres Riancho

+2

·

Publicado

2023-12-02

·

Atualizado

2026-02-21

·

CVE-2024-0133

CVSS v4.0

4.8

Média

VetorAV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions NVIDIA Container Toolkit versions 1.16.1 or earlier
Description The issue is related to the default mode of operation in NVIDIA Container Toolkit, allowing a specially crafted container image to create empty files on the host file system. This vulnerability does not impact use cases where CDI is used. A successful exploit may lead to data tampering. The vulnerability is also associated with a null pointer dereference due to concurrent access to a resource, potentially allowing a remote attacker to modify arbitrary data by using a specially crafted container image.
Recommendations For NVIDIA Container Toolkit versions 1.16.1 or earlier, consider updating to a version that contains a fix for this issue, as no specific workaround is provided in the given information. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

Time Of Check To Time Of Use

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

AZL-50181
AZL-50184
BDU:2024-09498
BDU:2025-10370
BDU:2025-10372
CVE-2024-0133
GHSA-F748-7HPG-88CH
GHSA-G4PJ-MX9F-M2MH
GO-2024-3237
OPENSUSE-SU-2024:0350-1
OPENSUSE-SU-2024:14458-1
OPENSUSE-SU-2024_3950-1
SUSE-SU-2024:3950-1
SUSE-SU-2025:4187-1
SUSE-SU-2026:0558-1

Produtos afetados

Nvidia Container Toolkit
Red Os
Suse