PT-2024-6648 · Nvidia+2 · Nvidia Container Toolkit+2

Published

2024-09-25

·

Updated

2026-02-17

·

CVE-2024-0132

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions NVIDIA Container Toolkit versions 1.16.1 and earlier
Description The NVIDIA Container Toolkit contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration, allowing a specifically crafted container image to gain access to the host file system. This vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. It is estimated that over 35% of cloud environments utilizing NVIDIA GPUs are at risk. The vulnerability has been exploited in real-world incidents, allowing attackers to break out of containers and gain full access to the host system.
Recommendations NVIDIA Container Toolkit version 1.16.1 and earlier: Upgrade to version 1.16.2 or later to fix the vulnerability. NVIDIA Container Toolkit version 1.17.4 and earlier: Update to the latest version and restrict access to privileged runtime sockets. As a temporary workaround, consider disabling the use of specifically crafted container images until a patch is available. Restrict access to the host file system to minimize the risk of exploitation.

Exploit

Fix

DoS

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-50160
AZL-50180
BDU:2024-07816
CVE-2024-0132
GHSA-536J-XXHG-6PGG
GHSA-MJJW-553X-87PQ
GO-2024-3239
OPENSUSE-SU-2024:0350-1
OPENSUSE-SU-2024:14458-1
OPENSUSE-SU-2024_3950-1
SUSE-SU-2024:3950-1
SUSE-SU-2025:4187-1
SUSE-SU-2025_4187-1
SUSE-SU-2026:0558-1

Affected Products

Nvidia Container Toolkit
Red Os
Suse