PT-2025-1566 · Nvidia+2 · Nvidia Container Toolkit+2

Andres Riancho

+2

·

Published

2025-01-16

·

Updated

2025-11-24

·

CVE-2024-0135

CVSS v3.1

7.6

High

VectorAV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NVIDIA Container Toolkit versions are affected, but specific versions are not provided in the input data.
Description The issue is related to an improper isolation vulnerability where a specially crafted container image could lead to modification of a host binary. A successful exploit may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. The "GET /api/v1/status/{job id}" and "POST /api/v1/search" API endpoints are mentioned, with the job id variable and Content-Type being relevant. No information is provided about the estimated number of potentially affected devices or real-world incidents.
Recommendations Since specific affected versions of NVIDIA Container Toolkit are not provided, a general recommendation based on the available data is to apply the latest security update released by NVIDIA for its Container Toolkit and GPU Operator to address the critical vulnerabilities.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-13807
CVE-2024-0135
SUSE-SU-2025:4187-1

Affected Products

Nvidia Container Toolkit
Red Os
Suse