Nvidia: tampering
Medium4.1CVE-2024-0133 · Published Oct 8, 2024
### Description NVIDIA Container Toolkit 1.16.1 or earlier contains a vulnerability in the default mode of operation allowing a specially crafted container image to create empty files on the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to data tampering. ### Patches The fix has been addressed in [`v1.16.2`](https://github.com/NVIDIA/libnvidia-container/releases/tag/v1.16.2) of the `libnvidia-container*` packages that are bundled with the [NVIDIA Container Toolkit v1.16.2](https://github.com/NVIDIA/nvidia-container-toolkit/releases/tag/v1.16.2). NVIDIA GPU Operator 24.6.2 supports NVIDIA Container Toolkit v1.16.2 and uses it by default. ### References * https://nvidia.custhelp.com/app/answers/detail/a_id/5582
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| NVIDIA GPU Operator Product | < 24.6.2 | 24.6.2 |
| libnvidia-container-tools Product | < 1.16.2 | 1.16.2 |
| libnvidia-container1 Product | < 1.16.2 | 1.16.2 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-367
More Nvidia advisories
All Nvidia| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 1 | Nvidia Megatron-Bridge: unsafe deserialization | High7.8 | No fix yet |
| Jul 1 | Nvidia Megatron-Bridge: unsafe deserialization | High7.8 | No fix yet |
| Jul 1 | Nvidia Megatron-Bridge: unsafe deserialization | High7.8 | No fix yet |
| Jul 1 | Nvidia BlueField GA: code execution | Critical9.0 | No fix yet |
| Jul 1 | Nvidia BlueField GA: code execution | Critical9.0 | No fix yet |
| Oct 82024 | Nvidia: race condition | Critical9.0 | 1.16.2+2 more |