CVE-2024-0137
MEDIUMNVIDIA Container Toolkit <1.17.3 & GPU Operator <24.9.1 - DoS & Privilege Escalation
Title source: llmDescription
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code running in the host’s network namespace. This vulnerability is present only when the NVIDIA Container Toolkit is configured in a nondefault way. A successful exploit of this vulnerability may lead to denial of service and escalation of privileges.
References (1)
Core 1
Core References
Mitigation, Vendor Advisory
https://nvidia.custhelp.com/app/answers/detail/a_id/5599
Scores
CVSS v3
5.5
EPSS
0.0007
EPSS Percentile
21.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-653
Status
published
Products (2)
nvidia/nvidia_container_toolkit
< 1.17.3
nvidia/nvidia_gpu_operator
< 24.9.1
Published
Jan 28, 2025
Tracked Since
Feb 18, 2026