CVE-2024-0132 is a Time-of-check Time-of-Use (TOCTOU) vulnerability in NVIDIA Container Toolkit versions 1.16.1 and earlier, impacting Linux systems using default configurations. This flaw allows a specially crafted container image to gain access to the host filesystem. With a CVSS score of 8.3 (HIGH), it presents a significant risk, potentially leading to code execution, denial of service, privilege escalation, information disclosure, and data tampering, with a network attack vector and high attack complexity. While not yet in the KEV catalog, public exploit code exists (EDB-52095), and it has garnered substantial community attention and media coverage, indicating a high potential for active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.16.2CPE matchmatch criteria | cpe:2.3:a:nvidia:nvidia_container_toolkit:*:*:*:*:*:*:*:* | ||
< 24.6.2CPE matchmatch criteria | cpe:2.3:a:nvidia:nvidia_gpu_operator:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
NVIDIA Container Toolkit contains a Time-of-check Time-of-Use (TOCTOU) vulnerability
Oct 29, 2024NVIDIA: CVE-2024-0132 Container Toolkit 1.16.1 and Earlier Time-of-check Time-of Use Vulnerability
Oct 8, 2024nvidia-container-toolkit: Time-of-check Time-of-use (TOCTOU) Race Condition in NVIDIA Container toolkit
Sep 26, 2024