CVE-2024-0134: NVIDIA Container Toolkit

Medium severity, CVSS 4.1. EPSS: 0.4% chance of exploitation in the next 30 days.

NVIDIA Container Toolkit and NVIDIA GPU Operator for Linux contain a UNIX vulnerability where a specially crafted container image can lead to the creation of unauthorized files on the host. The name and location of the files cannot be controlled by an attacker. A successful exploit of this vulnerability might lead to data tampering.

Affected products

  • NVIDIA NVIDIA Container Toolkit: before 1.17 (fixed in 1.17)
  • NVIDIA NVIDIA GPU Operator: before 24.9.0 (fixed in 24.9.0)

Published 2024-11-05. Last modified 2026-06-17.