First published: Tue Nov 05 2024(Updated: )
NVIDIA Container Toolkit and NVIDIA GPU Operator for Linux contain a UNIX vulnerability where a specially crafted container image can lead to the creation of unauthorized files on the host. The name and location of the files cannot be controlled by an attacker. A successful exploit of this vulnerability might lead to data tampering.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
NVIDIA Container Toolkit | <1.17 | |
NVIDIA GPU Operator | <24.9.0 | |
Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-0134 is categorized as high due to the potential for unauthorized file creation on the host.
To fix CVE-2024-0134, update the NVIDIA Container Toolkit to a version above 1.17 or the NVIDIA GPU Operator to a version above 24.9.0.
CVE-2024-0134 can lead to unauthorized file creation on the host system, which may affect system integrity.
CVE-2024-0134 affects NVIDIA Container Toolkit versions below 1.17 and NVIDIA GPU Operator versions below 24.9.0.
No, the Linux Kernel itself is not vulnerable under CVE-2024-0134.