CVE-2024-0134: Medium severity nvidia container toolkit vulnerability
NVIDIA Container Toolkit and NVIDIA GPU Operator for Linux contain a UNIX vulnerability where a specially crafted container image can lead to the creation of unauthorized files on the host. The name and location of the files cannot be controlled by an attacker. A successful exploit of this vulnerability might lead to data tampering.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0134?
The severity of CVE-2024-0134 is categorized as high due to the potential for unauthorized file creation on the host.
How do I fix CVE-2024-0134?
To fix CVE-2024-0134, update the NVIDIA Container Toolkit to a version above 1.17 or the NVIDIA GPU Operator to a version above 24.9.0.
What impact does CVE-2024-0134 have on my system?
CVE-2024-0134 can lead to unauthorized file creation on the host system, which may affect system integrity.
Which software is affected by CVE-2024-0134?
CVE-2024-0134 affects NVIDIA Container Toolkit versions below 1.17 and NVIDIA GPU Operator versions below 24.9.0.
Is the Linux Kernel vulnerable in CVE-2024-0134?
No, the Linux Kernel itself is not vulnerable under CVE-2024-0134.