PT-2023-9664 · Nvidia+2 · Nvidia Container Toolkit+2

Andres Riancho

+2

·

Published

2023-12-02

·

Updated

2026-02-21

·

CVE-2024-0133

CVSS v4.0

4.8

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions NVIDIA Container Toolkit versions 1.16.1 or earlier
Description The issue is related to the default mode of operation in NVIDIA Container Toolkit, allowing a specially crafted container image to create empty files on the host file system. This vulnerability does not impact use cases where CDI is used. A successful exploit may lead to data tampering. The vulnerability is also associated with a null pointer dereference due to concurrent access to a resource, potentially allowing a remote attacker to modify arbitrary data by using a specially crafted container image.
Recommendations For NVIDIA Container Toolkit versions 1.16.1 or earlier, consider updating to a version that contains a fix for this issue, as no specific workaround is provided in the given information. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

Time Of Check To Time Of Use

Resource Exhaustion

Weakness Enumeration

Related Identifiers

AZL-50181
AZL-50184
BDU:2024-09498
BDU:2025-10370
BDU:2025-10372
CVE-2024-0133
GHSA-F748-7HPG-88CH
GHSA-G4PJ-MX9F-M2MH
GO-2024-3237
OPENSUSE-SU-2024:0350-1
OPENSUSE-SU-2024:14458-1
OPENSUSE-SU-2024_3950-1
SUSE-SU-2024:3950-1
SUSE-SU-2025:4187-1
SUSE-SU-2026:0558-1

Affected Products

Nvidia Container Toolkit
Red Os
Suse