CVE-2024-0135
HIGHNVIDIA Container Toolkit < 1.17.3 and NVIDIA GPU Operator < 24.9.1 - Improper Isolation Leading to Code Execution
Title source: llmDescription
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to modification of a host binary. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
References (1)
Core 1
Core References
Mitigation, Vendor Advisory
https://nvidia.custhelp.com/app/answers/detail/a_id/5599
Scores
CVSS v3
7.6
EPSS
0.0010
EPSS Percentile
27.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-653
Status
published
Products (2)
nvidia/nvidia_container_toolkit
< 1.17.3
nvidia/nvidia_gpu_operator
< 24.9.1
Published
Jan 28, 2025
Tracked Since
Feb 18, 2026