CVE-2024-0133: NVIDIA Container Toolkit
Low severity, CVSS 3.4. EPSS: 0.2% chance of exploitation in the next 30 days.
NVIDIA Container Toolkit 1.16.1 or earlier contains a vulnerability in the default mode of operation allowing a specially crafted container image to create empty files on the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to data tampering.
Affected products
- NVIDIA NVIDIA Container Toolkit: before 1.16.2 (fixed in 1.16.2)
- NVIDIA NVIDIA GPU Operator: before 24.6.2 (fixed in 24.6.2)
Published 2024-09-26. Last modified 2026-06-17.