CVE-2024-0132: CVE-2025-23359: Nvidia-container-toolkit: GPU Container Escape (CVE-2024-0132 fix bypass)
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Other sources
NVIDIA: CVE-2024-0132 Container Toolkit 1.16.1 and Earlier Time-of-check Time-of Use Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0132?
CVE-2024-0132 is considered a critical vulnerability that allows a crafted container image to gain access to the host file system.
How do I fix CVE-2024-0132?
To mitigate CVE-2024-0132, upgrade the NVIDIA Container Toolkit to version 1.16.2 or later.
Which systems are affected by CVE-2024-0132?
CVE-2024-0132 affects NVIDIA Container Toolkit versions 1.16.1 and earlier, particularly when used with default configurations in various environments, including Azure Kubernetes and CBL Mariner.
What type of vulnerability is CVE-2024-0132?
CVE-2024-0132 is a Time-of-check Time-of-use (TOCTOU) vulnerability.
Does CVE-2024-0132 affect all use cases of NVIDIA Container Toolkit?
No, CVE-2024-0132 does not impact use cases where Container Device Interface (CDI) is utilized.