Skip to content
NvidiaGHSA-95rf-r6p4-44h7

Nvidia: race condition

Critical9.0CVE-2024-0132 · Published Oct 8, 2024

### Description NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. ### Patches The fix has been addressed in [`v1.16.2`](https://github.com/NVIDIA/libnvidia-container/releases/tag/v1.16.2) of the `libnvidia-container*` packages that are bundled with the [NVIDIA Container Toolkit v1.16.2](https://github.com/NVIDIA/nvidia-container-toolkit/releases/tag/v1.16.2). NVIDIA GPU Operator 24.6.2 supports NVIDIA Container Toolkit v1.16.2 and uses it by default. ### References * https://nvidia.custhelp.com/app/answers/detail/a_id/5582

GitHub advisory

Affected versions

PackageAffectedFixed in
NVIDIA GPU Operator
Product
< 24.6.224.6.2
libnvidia-container-tools
Product
< 1.16.21.16.2
libnvidia-container1
Product
< 1.16.21.16.2
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-367

More Nvidia advisories

All Nvidia
Advisory
Nvidia Megatron-Bridge: unsafe deserialization
High7.8Jul 1
Nvidia Megatron-Bridge: unsafe deserialization
High7.8Jul 1
Nvidia Megatron-Bridge: unsafe deserialization
High7.8Jul 1
Nvidia BlueField GA: code execution
Critical9.0Jul 1
Nvidia BlueField GA: code execution
Critical9.0Jul 1
Nvidia: tampering
Medium4.1Oct 8, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.