Nvidia: race condition
Critical9.0CVE-2024-0132 · Published Oct 8, 2024
### Description NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. ### Patches The fix has been addressed in [`v1.16.2`](https://github.com/NVIDIA/libnvidia-container/releases/tag/v1.16.2) of the `libnvidia-container*` packages that are bundled with the [NVIDIA Container Toolkit v1.16.2](https://github.com/NVIDIA/nvidia-container-toolkit/releases/tag/v1.16.2). NVIDIA GPU Operator 24.6.2 supports NVIDIA Container Toolkit v1.16.2 and uses it by default. ### References * https://nvidia.custhelp.com/app/answers/detail/a_id/5582
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| NVIDIA GPU Operator Product | < 24.6.2 | 24.6.2 |
| libnvidia-container-tools Product | < 1.16.2 | 1.16.2 |
| libnvidia-container1 Product | < 1.16.2 | 1.16.2 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-367
More Nvidia advisories
All Nvidia| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 1 | Nvidia Megatron-Bridge: unsafe deserialization | High7.8 | No fix yet |
| Jul 1 | Nvidia Megatron-Bridge: unsafe deserialization | High7.8 | No fix yet |
| Jul 1 | Nvidia Megatron-Bridge: unsafe deserialization | High7.8 | No fix yet |
| Jul 1 | Nvidia BlueField GA: code execution | Critical9.0 | No fix yet |
| Jul 1 | Nvidia BlueField GA: code execution | Critical9.0 | No fix yet |
| Oct 82024 | Nvidia: tampering | Medium4.1 | 1.16.2+2 more |