CVE-2024-0136 is an improper isolation vulnerability in the NVIDIA Container Toolkit, affecting Linux systems utilizing NVIDIA Container Toolkit, NVIDIA GPU Operator, and the Linux kernel. This high-severity vulnerability (CVSS 8.4) allows a specially crafted container image to gain read and write access to host devices, potentially leading to code execution, denial of service, privilege escalation, information disclosure, and data tampering, but only when the toolkit is non-default configured. While there is no known active exploitation or public exploit code, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.17.3CPE matchmatch criteria | cpe:2.3:a:nvidia:nvidia_container_toolkit:*:*:*:*:*:*:*:* | ||
< 24.9.1CPE matchmatch criteria | cpe:2.3:a:nvidia:nvidia_gpu_operator:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.