Vulnerability CVE-2024-0132


Published: 2024-09-26

Description:
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
NVIDIA Container Toolkit 1.16.1 Time-of-check Time-of-Use (TOCTOU)
r0binak
30.03.2025

 References:
https://nvidia.custhelp.com/app/answers/detail/a_id/5582

Copyright 2025, cxsecurity.com

 

Back to Top