CVE-2024-0133

EUVD-2024-3026
NVIDIA Container Toolkit 1.16.1 or earlier contains a vulnerability in the default mode of operation allowing a specially crafted container image to create empty files on the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to data tampering.
TOCTOU
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.1 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 70%
Affected Products (NVD)
VendorProductVersion
nvidianvidia_container_toolkit
𝑥
< 1.16.2
nvidianvidia_gpu_operator
𝑥
< 24.6.2
𝑥
= Vulnerable software versions
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libnvidia-container-devel
suse enterprise sap 15 SP4
1.18.0-150200.5.9.1
fixed
suse enterprise sap 15 SP5
1.18.0-150200.5.9.1
fixed
suse enterprise sap 15 SP7
1.18.0-150200.5.9.1
fixed
suse enterprise server 15 SP4
1.18.0-150200.5.9.1
fixed
suse enterprise server 15 SP5
1.18.0-150200.5.9.1
fixed
suse enterprise server 15 SP6
1.18.0-150200.5.9.1
fixed
suse enterprise server 15 SP7
1.18.0-150200.5.9.1
fixed
libnvidia-container-static
suse enterprise sap 15 SP4
1.18.0-150200.5.9.1
fixed
suse enterprise sap 15 SP5
1.18.0-150200.5.9.1
fixed
suse enterprise sap 15 SP7
1.18.0-150200.5.9.1
fixed
suse enterprise server 15 SP4
1.18.0-150200.5.9.1
fixed
suse enterprise server 15 SP5
1.18.0-150200.5.9.1
fixed
suse enterprise server 15 SP6
1.18.0-150200.5.9.1
fixed
suse enterprise server 15 SP7
1.18.0-150200.5.9.1
fixed
libnvidia-container-tools
suse enterprise sap 15 SP4
1.18.0-150200.5.9.1
fixed
suse enterprise sap 15 SP5
1.18.0-150200.5.9.1
fixed
suse enterprise sap 15 SP7
1.18.0-150200.5.9.1
fixed
suse enterprise server 15 SP4
1.18.0-150200.5.9.1
fixed
suse enterprise server 15 SP5
1.18.0-150200.5.9.1
fixed
suse enterprise server 15 SP6
1.18.0-150200.5.9.1
fixed
suse enterprise server 15 SP7
1.18.0-150200.5.9.1
fixed
libnvidia-container1
suse enterprise sap 15 SP4
1.18.0-150200.5.9.1
fixed
suse enterprise sap 15 SP5
1.18.0-150200.5.9.1
fixed
suse enterprise sap 15 SP7
1.18.0-150200.5.9.1
fixed
suse enterprise server 15 SP4
1.18.0-150200.5.9.1
fixed
suse enterprise server 15 SP5
1.18.0-150200.5.9.1
fixed
suse enterprise server 15 SP6
1.18.0-150200.5.9.1
fixed
suse enterprise server 15 SP7
1.18.0-150200.5.9.1
fixed
nvidia-container-toolkit
suse enterprise sap 15 SP4
1.18.0-150200.5.17.1
fixed
suse enterprise sap 15 SP5
1.18.0-150200.5.17.1
fixed
suse enterprise sap 15 SP7
1.18.0-150200.5.17.1
fixed
suse enterprise server 15 SP4
1.18.0-150200.5.17.1
fixed
suse enterprise server 15 SP5
1.18.0-150200.5.17.1
fixed
suse enterprise server 15 SP7
1.18.0-150200.5.17.1
fixed