CVE-2024-0132: NVIDIA Container Toolkit
High severity, CVSS 8.3. EPSS: 40.8% chance of exploitation in the next 30 days.
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Affected products
- NVIDIA NVIDIA Container Toolkit: before 1.16.2 (fixed in 1.16.2)
- NVIDIA NVIDIA GPU Operator: before 24.6.2 (fixed in 24.6.2)
Published 2024-09-26. Last modified 2026-06-17.