CVE-2024-0133

NVIDIA Container Toolkit 1.16.1 or earlier contains a vulnerability in the default mode of operation allowing a specially crafted container image to create empty files on the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to data tampering.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:nvidia:nvidia_container_toolkit:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:nvidia:nvidia_gpu_operator:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

02 Oct 2024, 14:43

Type Values Removed Values Added
CPE cpe:2.3:a:nvidia:nvidia_gpu_operator:*:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:nvidia_container_toolkit:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
First Time Nvidia nvidia Container Toolkit
Linux linux Kernel
Nvidia
Linux
Nvidia nvidia Gpu Operator
References () https://nvidia.custhelp.com/app/answers/detail/a_id/5582 - () https://nvidia.custhelp.com/app/answers/detail/a_id/5582 - Vendor Advisory
CVSS v2 : unknown
v3 : 4.1
v2 : unknown
v3 : 3.4

26 Sep 2024, 13:32

Type Values Removed Values Added
Summary
  • (es) NVIDIA Container Toolkit 1.16.1 o versiones anteriores contienen una vulnerabilidad en el modo de funcionamiento predeterminado que permite que una imagen de contenedor especialmente manipulada cree archivos vacíos en el sistema de archivos del host. Esto no afecta a los casos de uso en los que se utiliza CDI. Una explotación exitosa de esta vulnerabilidad puede provocar la manipulación de datos.

26 Sep 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-26 06:15

Updated : 2024-10-02 14:43


NVD link : CVE-2024-0133

Mitre link : CVE-2024-0133

CVE.ORG link : CVE-2024-0133


JSON object : View

Products Affected

nvidia

  • nvidia_gpu_operator
  • nvidia_container_toolkit

linux

  • linux_kernel
CWE
CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition