NVIDIA Container Toolkit and NVIDIA GPU Operator for Linux contain a UNIX vulnerability where a specially crafted container image can lead to the creation of unauthorized files on the host. The name and location of the files cannot be controlled by an attacker. A successful exploit of this vulnerability might lead to data tampering.
Metrics
Affected Vendors & Products
References
History
Fri, 08 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Linux
Linux linux Kernel Nvidia Nvidia nvidia Container Toolkit Nvidia nvidia Gpu Operator |
|
Weaknesses | NVD-CWE-Other | |
CPEs | cpe:2.3:a:nvidia:nvidia_container_toolkit:*:*:*:*:*:*:*:* cpe:2.3:a:nvidia:nvidia_gpu_operator:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* |
|
Vendors & Products |
Linux
Linux linux Kernel Nvidia Nvidia nvidia Container Toolkit Nvidia nvidia Gpu Operator |
Wed, 06 Nov 2024 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | nvidia-container-toolkit: specially-crafted container image can lead to the creation of unauthorized files on the host | |
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Tue, 05 Nov 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 05 Nov 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | NVIDIA Container Toolkit and NVIDIA GPU Operator for Linux contain a UNIX vulnerability where a specially crafted container image can lead to the creation of unauthorized files on the host. The name and location of the files cannot be controlled by an attacker. A successful exploit of this vulnerability might lead to data tampering. | |
Weaknesses | CWE-61 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: nvidia
Published: 2024-11-05T18:37:31.699Z
Updated: 2024-11-05T18:52:00.366Z
Reserved: 2023-12-02T00:42:44.854Z
Link: CVE-2024-0134
Vulnrichment
Updated: 2024-11-05T18:51:56.051Z
NVD
Status : Analyzed
Published: 2024-11-05T19:15:05.203
Modified: 2024-11-08T15:53:40.200
Link: CVE-2024-0134
Redhat