CVE-2024-0134 PUBLISHED CVSS 4.099999904632568 MEDIUM

NVIDIA Container Toolkit and NVIDIA GPU Operator for Linux contain a UNIX vulnerability where a specially crafted container image can lead to the creation of unauthorized files on the host. The name and location of the files cannot be controlled by an attacker. A successful exploit of this vulnerability might lead to data tampering.

EPSS 0.23% · 46.0th percentile

Risk Scores

CVSS v3.1
4.099999904632568
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N
EPSS Score
0.23%
46.0th percentile

Affected Products

VendorProductVersions
nvidianvidia_container_toolkit0
NVIDIANVIDIA GPU OperatorAll versions up to and including 24.6.2
nvidianvidia_gpu_operator0
NVIDIANVIDIA Container ToolkitAll versions up to and including v1.16.2

Timeline

References

Open in Interactive Console →