CVE-2024-0137 is an improper isolation vulnerability in the NVIDIA Container Toolkit, affecting various Linux distributions and NVIDIA products. This flaw allows a specially crafted container image to execute untrusted code within the host's network namespace, but only when the toolkit is configured non-default. Rated Medium severity (CVSS 6.5), a successful exploit could lead to denial of service and privilege escalation. There is no evidence of active exploitation, no public exploit code, and minimal community discussion or media coverage beyond a single article.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.17.3CPE matchmatch criteria | cpe:2.3:a:nvidia:nvidia_container_toolkit:*:*:*:*:*:*:*:* | ||
< 24.9.1CPE matchmatch criteria | cpe:2.3:a:nvidia:nvidia_gpu_operator:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.