CVE-2024-0133 affects NVIDIA Container Toolkit versions 1.16.1 and earlier, as well as related NVIDIA Linux kernel and GPU operator products. This vulnerability allows a specially crafted container image to create empty files on the host filesystem, potentially leading to data tampering. It has a low CVSS score of 3.4, indicating a network attack vector with high attack complexity and requiring user interaction. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.16.2CPE matchmatch criteria | cpe:2.3:a:nvidia:nvidia_container_toolkit:*:*:*:*:*:*:*:* | ||
< 24.6.2CPE matchmatch criteria | cpe:2.3:a:nvidia:nvidia_gpu_operator:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.
NVIDIA Container Toolkit allows specially crafted container image to create empty files on the host file system
Oct 29, 2024CVE-2024-0133
Oct 8, 2024nvidia-container-toolkit: Data tampering in NVIDIA Container Toolkit
Sep 26, 2024NVIDIA Container Toolkit 1.16.1 or earlier contains a vulnerability in the default mode of operation allowing a specially crafted container image to create empty files on the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to data tampering.
Sep 10, 2024