PT-2023-9664 · Nvidia+2 · Nvidia Container Toolkit+2
Andres Riancho
+2
·
Published
2023-12-02
·
Updated
2026-02-21
·
CVE-2024-0133
CVSS v4.0
4.8
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
NVIDIA Container Toolkit versions 1.16.1 or earlier
Description
The issue is related to the default mode of operation in NVIDIA Container Toolkit, allowing a specially crafted container image to create empty files on the host file system. This vulnerability does not impact use cases where CDI is used. A successful exploit may lead to data tampering. The vulnerability is also associated with a null pointer dereference due to concurrent access to a resource, potentially allowing a remote attacker to modify arbitrary data by using a specially crafted container image.
Recommendations
For NVIDIA Container Toolkit versions 1.16.1 or earlier, consider updating to a version that contains a fix for this issue, as no specific workaround is provided in the given information. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Permission
Time Of Check To Time Of Use
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nvidia Container Toolkit
Red Os
Suse