CVE-2024-0135 describes an improper isolation vulnerability within the NVIDIA Container Toolkit, affecting various Linux distributions and NVIDIA products including the Container Toolkit and GPU Operator. This high-severity vulnerability (CVSS 7.6) can be exploited by a specially crafted container image, potentially leading to remote code execution, denial of service, privilege escalation, information disclosure, and data tampering. While the attack complexity is high and user interaction is required, the potential impact is significant. Currently, there is no evidence of active exploitation, nor are there public exploits available in Metasploit, Nuclei, or ExploitDB, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.17.3CPE matchmatch criteria | cpe:2.3:a:nvidia:nvidia_container_toolkit:*:*:*:*:*:*:*:* | ||
< 24.9.1CPE matchmatch criteria | cpe:2.3:a:nvidia:nvidia_gpu_operator:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.4 Bluesky, 0.1 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.